Skip to main content
ighita
Staff
Staff
November 30, 2022

Troubleshooting Tip: FortiGate configuration to allow EMS to import a Web Filter profile from FortiOS

  • November 30, 2022
  • 0 replies
  • 1435 views
Description

This article explains a case where, after configuring the FortiClient EMS to import a Web Filter profile from FortiOS, the traffic is dropped by the local-in policy.

Scope

FortiGate and EMS FortiClient

Solution

Importing a Web Filter profile from FortiOS requires HTTPS access on the FortiGate interface.

 

In cases where trusted hosts are configured for the user, it is necessary to add the EMS IP to the trusted host list.

To identify the trusted hosts, go to System -> Administrators, select the administrator account to edit, check Restrict login to trusted hosts is enabled, and add, if it's necessary, the EMS IP addresses.

 

ighita_0-1669820583577.png

 

To do this in the CLI, run the following:

 

# config system admin

edit <administrator-name>

set trustedhost1 <ip and subnet>

end

 

The EMS FortiClient is using the HTTPS admin port configured on the FortiGate to import the profile.

Go to System -> Settings -> Administrator Settings and check the HTTPS port.

 

ighita_1-1669820880781.png

 

To do this in the CLI, run the following:

 

# config system global

set admin-sport <port>

 

Related article:

https://docs.fortinet.com/document/forticlient/7.0.1/ems-administration-guide/455661/importing-a-web-filter-profile-from-fortios-or-fortimanager

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!