Skip to main content
ighita
Staff
Staff
November 30, 2022

Troubleshooting Tip: FortiGate configuration to allow FortiClient EMS to import a Web Filter profile from FortiOS

  • November 30, 2022
  • 0 replies
  • 1469 views

Description

This article explains a case where, after configuring the FortiClient EMS to import a Web Filter profile from FortiOS, the traffic is dropped by the local-in policy.

Scope

FortiGate and FortiClient EMS.

Solution

Importing a Web Filter profile from FortiOS requires HTTPS access on the FortiGate interface.

FortiClient EMS displays the error message 'Connected to server but failed to find specified Site' if HTTPS access is not enabled on the FortiGate interface facing the FortiClient EMS or if the configured HTTPS port does not match the FortiGate HTTPS administrative port.

142c2f1c.png


In cases where trusted hosts are configured for the user, it is necessary to add the EMS IP to the trusted host list.

To identify the trusted hosts, go to System -> Administrators, select the administrator account to edit, check Restrict login to trusted hosts is enabled, and add, if it is necessary, the EMS IP addresses.
 

ighita_0-1669820583577.png

 
To do this in the CLI, run the following:

config system admin
    edit <administrator-name>
        set trustedhost1 <ip and subnet>
end

 
The FortiClient EMS is using the HTTPS admin port configured on the FortiGate to import the profile.

Go to System -> Settings -> Administrator Settings and check the HTTPS port.

 

ighita_1-1669820880781.png

 

To do this in the CLI, run the following:

 

config system global
    set admin-sport <port>
end


Related article:

Importing a Web Filter profile from FortiOS or FortiManager

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!