Fortinet black logo

User Guide

IP matching

24.2.0
Copy Link
Copy Doc ID af1daa65-c273-11ec-9fd1-fa163e15d75b:54619
Download PDF

IP matching

The FortiMonitor Agent has default IP matching which fires during the initial handshake. This IP matching can be helpful or the following scenarios:

  • If a user may have uninstalled the Agent and is looking to reinstall. Rather than creating a new entry/object, we would want to attach the Agent to the same server as before to avoid duplication and keep all historical data. This works by the Agent sending the IP addresses of the instance to our cloud, and then we check to see if those IPs exist in your account. If they do, we automatically attach the Agent back to that particular server.

  • For users moving on from basic instances (without the Agent) to advanced instances. In this case, instead of the Agent setting up a new instance (duplicating the existing instance), the IP matching would step in and assign the Agent to the server with the matching IP.

However, this can backfire in cases with multiple networks and overlapping IP ranges. If you happen to have the same IP in separate networks monitored by FortiMonitor, you can disable IP matching. The option is called disable_server_match and is further documented here.

IP matching

The FortiMonitor Agent has default IP matching which fires during the initial handshake. This IP matching can be helpful or the following scenarios:

  • If a user may have uninstalled the Agent and is looking to reinstall. Rather than creating a new entry/object, we would want to attach the Agent to the same server as before to avoid duplication and keep all historical data. This works by the Agent sending the IP addresses of the instance to our cloud, and then we check to see if those IPs exist in your account. If they do, we automatically attach the Agent back to that particular server.

  • For users moving on from basic instances (without the Agent) to advanced instances. In this case, instead of the Agent setting up a new instance (duplicating the existing instance), the IP matching would step in and assign the Agent to the server with the matching IP.

However, this can backfire in cases with multiple networks and overlapping IP ranges. If you happen to have the same IP in separate networks monitored by FortiMonitor, you can disable IP matching. The option is called disable_server_match and is further documented here.