Skip to main content
osaleem2_10
Explorer III
November 8, 2023
Solved

EMS Manual patch

  • November 8, 2023
  • 5 replies
  • 5241 views

I did FortiEMS deployment and installed Forticlient for 1000 machines. After I did Vulnerability scanning im got some Vul with Auto and others as manual.

 

My question is, how can I do manual patching through EMS? Is there a way to install the patch from the internet manually and upload the MSI or patch file to EMS to push it automatically to all machines? OR does manual patching mean that users have to do it by themselves only?

In addition, can I create a custom message to show to users once they log in to their machines including a message and link to download the patch of vulnerability manually?

 

#ems #vulnerability #patch

Best answer by Blkktivity

Hello,

 

FortiClient's vulnerability patching can only patch applications that can be tasked with patching.
FortiClient itself does not perform the patching, rather, it tasks the Application to contact its own update server to download and update itself.
If the Application cannot be tasked, FortiClient will display that the patching requires manual patching.
If an Application is auto-patched and requires a reboot to complete its action, this is relayed to the FortiClient which in turn relays it to the user.
In all of this, FortiClient's role is that of a conductor; it only directs the required actions needed to the Application.
If patching is needed to a certain level (ie. critical), FortiClient searches the Vulnerability list for all critical Vulnerabilities, and then searches for installed Applications matching the vulnerability list; each Application is then tasked to perform its own update as required.

Please see here for more information on the vulnerability scan feature- https://docs.fortinet.com/document/forticlient/7.2.2/ems-administration-guide/202270/vulnerability-scan

 

Hope this helps :)

5 replies

Stephen_G
Staff & Editor
Staff & Editor
November 11, 2023

Hello osaleem2_10,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Stephen_G - Fortinet Community Team
Stephen_G
Staff & Editor
Staff & Editor
November 13, 2023

Hello,

 

We are still looking for someone to help you.

We will come back to you ASAP.


Regards,

Stephen_G - Fortinet Community Team
peisenberg
Staff
Staff
November 13, 2023

1. Manual mean its intended to be done manually by administrator. Ems cannot push sw payload to endpoints 

2. I think Yes but not via EMS. 

Blkktivity
Staff
Staff
November 13, 2023

Hello,

 

FortiClient's vulnerability patching can only patch applications that can be tasked with patching.
FortiClient itself does not perform the patching, rather, it tasks the Application to contact its own update server to download and update itself.
If the Application cannot be tasked, FortiClient will display that the patching requires manual patching.
If an Application is auto-patched and requires a reboot to complete its action, this is relayed to the FortiClient which in turn relays it to the user.
In all of this, FortiClient's role is that of a conductor; it only directs the required actions needed to the Application.
If patching is needed to a certain level (ie. critical), FortiClient searches the Vulnerability list for all critical Vulnerabilities, and then searches for installed Applications matching the vulnerability list; each Application is then tasked to perform its own update as required.

Please see here for more information on the vulnerability scan feature- https://docs.fortinet.com/document/forticlient/7.2.2/ems-administration-guide/202270/vulnerability-scan

 

Hope this helps :)

osaleem2_10
Explorer III
November 13, 2023

thanks Blkktivity. 

 

appreciate your explanation.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!