Skip to main content
adriellousada
Staff
Staff
June 10, 2025

Technical Tip: Importing web filter profiles from FortiGate to FortiClient EMS

  • June 10, 2025
  • 0 replies
  • 1781 views
Description This article outlines how to import the default and custom categories from FortiGate to FortiClient EMS.
Scope FortiClient EMS and FortiGate.
Solution

FortiGate requirements:

 

Important:

HTTPS access must be permitted by FortiGate to effectively import Web Filter profiles from FortiOS to FortiClient EMS.

 

In FortiGate:

  1. Go to Network -> Interfaces.

  2. Select the desired port.

  3. Under Administrative Access, check the HTTPS option.

 

check-https.png

 

If the admin account that will be used for the import is configured with a trusted host, add the IP from where the connection attempt will originate. If using EMS Cloud, add the Cloud IP: FortiClient Cloud Portal > -About.

 

TrustedHost.png

 

Related document:

Allowlisting the FortiClient Cloud IP addresses   

 

Importing Web Filter Profile:

 
Steps to Import a Web Filter Profile from FortiGate to EMS:
  1. On FortiGate, navigate to Security Profiles -> Web Filter.
  2. On EMS, go to Endpoint Profiles -> Web Filter -> Import -> From FortiGate/FortiManager.

 

ems-web-filter.png

 

In the screen that appears, fill out the following fields:
 

ems-fgt.png

 

The FortiGate's configured Web Filter profiles will be listed.

 

web-filter-list.png


Select the profiles that will be imported into FortiClient EMS and select Next.
 

 

Select the Synchronization Mode and select Import:

 

import-web-filter-fgt.png

 

The chosen profiles will be imported by EMS and shown in a group called FortiGate named after the source under Endpoint Profiles -> Manage Profiles.

 

Checking custom category import.

 

Additionally, custom categories are imported. The URLs added to each custom category, however, will be displayed in the exclusion list with the same configured action rather than in the category list. This is demonstrated in the following example:

 

  • Category created in FortiGate:

 

web-filter-custom-action.png


custom-category.png
custom-url.png

 

  • Example of the same category after being imported into EMS:


ems-exclusion-list.png

 

Note that the same URL was imported with the deny action, as originally configured in the FortiGate. 

 

Note:

Starting with FortiOS 7.6.4, importing web filter profiles into FortiClient EMS using FortiGate GUI administrator credentials is no longer supported. To address this, FortiClient EMS 7.4.6 and later introduce a new method that uses a REST API key for secure integration.

To successfully import web filter profiles, EMS must be running version 7.4.6 or later, and a REST API administrator account must be configured on the FortiGate.

 

Steps:

 

1) Navigate to System -> Administrators -> Create New -> REST API Admin -> enter the Username -> select super_admin_readonly for Administrator Profile -> unselect PKI Group -> copy the new API Key somewhere safe.

 

babakmh_0-1774389925121.png

 

 

2) EMS GUI -> Endpoint Profiles -> Web filter -> Import -> import from FortiGate / FortiManager ->enter IP address of FortiGate -> select API Key for Authentication Type ->paste the API Key copied from the previous step.

 

babakmh_1-1774389925103.png

 

Related articles:

Technical Tip: How to create a REST API Admin user and assign it to an admin profile

FortiClient 7.4.5 EMS Release Notes

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!