Skip to main content
ck_FTNT
Staff
Staff
November 26, 2018

Technical Tip: FortiClient EMS Migration

  • November 26, 2018
  • 0 replies
  • 23719 views

Description

 

This article describes the steps necessary to migrate a FortiClient EMS Server to a new server based on 3 scenarios.

Scope

 

FortiClient EMS.


Solution

 

  1. A new FortiClient EMS will have the same IP address as the existing FortiClient EMS.

  2. A new FortiClient EMS will have a different IP address than the existing FortiClient EMS:
    • Using an IP address for registration.
    • Using FQDN for registration.

  3. The current FortiClient EMS is not accessible:
    • Using an IP address for registration.
    • Using FQDN for registration.


Same IP address:

  1. Create a backup of the FortiClient EMS database. This will create a .ENC file which can only be restored to a FortiClient EMS of the same version. For example: a backup from a v1.2.5 FortiClient EMS can only be restored to another v1.2.5 FortiClient EMS.

  2. Install the same version of FortiClient EMS on a new server and apply the license. See 'Licensing FortiClient EMS' in the FortiClient EMS admin guide.
    Note: It will be necessary to call customer service (1-866-648-4638) to have the license file updated to reflect the new Hardware ID of the server. The hardware ID can be found under Administration -> Upgrade License. When logged into the support site, it will be necessary to log out and back in after the license is updated.

  3. Restore the database backup.

  4. Cut over so the old FortiClient EMS is no longer reachable, and the new one is.

  5. Clients will register to the new FortiClient EMS transparently.


Different IP address:

Using an IP address for FortiClient registration:

  1. The existing FortiClient EMS is on IP x.x.x.x.

  2. Create a backup of the FortiClient EMS database. This will create a .ENC file which can only be restored to a FortiClient EMS of the same version. Meaning, a backup from a v1.2.5 FortiClient EMS can only be restored to another v1.2.5 FortiClient EMS.

  3. Install the same version of FortiClient EMS on a new server with IP address y.y.y.y and apply the license. See 'Licensing FortiClient EMS' in the FortiClient EMS admin guide.
    Note: It is necessary to call customer service (1-866-648-4638) to have a license file updated to reflect the new Hardware ID of the server. The hardware ID can be found under Administration -> Upgrade License. When logged into the support site, it is necessary to log out and back in after the license is updated.

  4. Restore the database backup.

  5. Update the 'Listen on IP' and FortiClient download URL settings.


Server_Settings.png

 

  1. Create a Gateway List on the old server with y.y.y.y specified in 'IP addresses/Hostnames'.

  2. Apply this gateway list to any endpoints intended for migration.
 
Using FQDN for FortiClient registration:
 
Note: To use FQDN for FortiClient connections, please review 'Configuring Server settings' section of the FortiClient EMS admin guide.

 

  1. The Existing FortiClient EMS is on IP address x.x.x.x, using FQDN 'EMS.domain.com'.

  2. Create a backup of the FortiClient EMS database. This will create a .ENC file which can only be restored to a FortiClient EMS of the same version. For example: a backup from a v1.2.5 FortiClient EMS can only be restored to another v1.2.5 FortiClient EMS.

  3. Install the same version of FortiClient EMS on a new server with IP address y.y.y.y and apply the license. See 'Licensing FortiClient EMS' in the FortiClient EMS admin guide.
    Note: It will be necessary to call customer service (1-866-648-4638) to have the license file updated to reflect the new Hardware ID of the server. The hardware ID can be found under Administration -> Upgrade License. When logged into the support site, it will be necessary to log out and back in after the license is updated.

  4. Restore the database backup.

  5. Update the 'Listen on IP' and FortiClient download URL settings.


Server_Settings.png

 

  1. Update the DNS record so EMS.domain.com now resolves to y.y.y.y.

 

The current FortiClient EMS is not accessible:
 
In some cases, FortiClient EMS will no longer be accessible. For example, in cases where the password is lost or the server has crashed and is not recoverable.
 
Using an IP address for FortiClient registration:
  1. The existing FortiClient EMS is on IP address x.x.x.x.

  2. Install FortiClient EMS on IP address y.y.y.y and apply the license. See 'Licensing FortiClient EMS' in the FortiClient EMS admin guide.
    Note: It will be necessary to call customer service (1-866-648-4638) to have the license file updated to reflect the new Hardware ID of the server. The hardware ID can be found under Administration -> Upgrade License. When logged into the support site, it will be necessary to log out and back in after the license is updated.

  3. Create any profiles to assign to endpoints after migrating.

  4. Import the domain (if applicable) and assign profiles to groups/OUs as appropriate.

  5. Redirect the registration/keep-alive traffic to the new IP address. If the endpoint traffic uses a FortiGate to route to the FortiClient EMS, use a VIP as follows:


mforbes_VIP.png

 

  1. Create a Gateway List which has the FortiClient EMS' IP address specified in 'IP addresses/Hostnames'.

  2. When the endpoints sync this Gateway List, they will begin to communicate directly with y.y.y.y. The VIP can be deleted at this stage.
 
Using an IP address for FortiClient registration:
 

Note: To use FQDN for FortiClient connections, see the 'Configuring EMS settings' section of the FortiClient EMS admin guide

 
  1. The Existing FortiClient EMS is on the IP x.x.x.x.

  2. Install FortiClient EMS on IP address y.y.y.y and apply the license. See 'Licensing FortiClient EMS' in the FortiClient EMS admin guide.
    Note: It will be necessary to call customer service (1-866-648-4638) to have the license file updated to reflect the new Hardware ID of the server. The hardware ID can be found under Administration -> Upgrade License. When logged into the support site, it will be necessary to log out and back in after the license is updated.

  3. Create any profiles to have assigned to endpoints after migrating.

  4. Import a domain (if applicable) and assign profiles as appropriate.

  5. Update the DNS record so it now resolves to y.y.y.y.

 

Notes:

Fortinet Migration process for Linux or after VM changing the server location:

Linux or VM 

 

Related article:

Technical Tip: Fixing the Collation Issues Due to Different Localization Configuration on the Windows Server