Skip to main content
jie
Staff
Staff
December 5, 2025

Technical Tip: Identifying Registry value of IPS engine version check on Windows Endpoints with ZTNA Tags

  • December 5, 2025
  • 0 replies
  • 201 views
Description This article describes how to detect the registry value of the IPS engine version check on a Windows endpoint by using the ZTNA tag.
Scope FortiClient, FortiClient EMS v7.4.
Solution

Go to FortiClient EMS -> Security Posture Tags -> Tags and select 'Create' to create a new ZTNA tagging rule.

 

1.PNG

 

Go to the endpoint machine, under registry location: 'Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Fortinet\FortiClient\FA_FW' and find out the current engine version.

 

1.PNG

 

ZTNA Tag Logic is shown as below:

 

1.PNG

 

Save this creation, and the result comes out as shown in the screenshots below.

 

EMS:

 

1.PNG

 

FortiClient:

 

1.PNG

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!