Skip to main content
verdas
New Member
July 3, 2026
Question

FortiClient 8

  • July 3, 2026
  • 2 replies
  • 75 views

My organization has been using FortiClient free version for the past 5-6 years. I have been following the semi-official deprecation of the free version for the past few months. We have been using 7.4.3 now for a few weeks.

Now FortiClient 8 has been released and I see no free version (what I assumed would be the case).

Quantum Cryptography is becoming front and center in planning for our future with Google and Microsoft saying they should be fully or mostly using PQC by end of 2029. Naturally, FC 8 has PQC support.

I wonder what everyone else who is or recently was using the FC free version is planning to do.

I know we could get a license for on-prem EMS (but that would be another server to setup and maintain for our small team and there were just two high profile vulnerabilities in it just a couple months ago), or get Fortinet Hosted EMS (but not sure of the price with that), or drop FC altogether and go with a different VPN solution or SASE option etc.

We have two dialup IPsec tunnels right now, one for employees using organization machines and one for contractors that has a more limited scope of what can be accessed.

Trying to get ideas to present to management with expected costs and pros/cons. What is everyone else planning to do or what did you do at your organization? 

    2 replies

    Toshi_Esumi
    SuperUser
    SuperUser
    July 3, 2026

    If you want to deploy any kind of endpoint control, or any security features that requires endpoint control, you have to deploy something like FortiClient EMS. If you just want to have IPsec VPN connectivity (without over TCP feature), FCT VPN 7.4.3 should be good enough.

    Toshi 

    Yurisk
    SuperUser
    SuperUser
    July 4, 2026

    Most of our clients postponed this decision until later, namely most of them still use SSL VPN (no current vulnerabilities, very trouble-free in maintaining, unlike IPSec, and 7.4 where it works is supported up to November 2028). 2-3-4 years from now is basically a lifetime of a given Fortigate model, so when by then, clients will refresh/upgrade their FGTs anyway and will then decide what to do about that. 

    Those seeking temporary solution, gradually switching to IPSec with free FC - Fortinet do not shut down older versions support, even with FortiOS 7.6.x Forticlient 7.2 works just fine, only need to download full installer from Support. If they, in the future, decide to stay with Fortigate for the Remote Access, most probably will just buy new Standalone FC license that gets you all updates to FC w/o head ache of managing EMS. 

    Those who think even further ahead, mostly made decision to get rid of/separate Remote Access in the traditional form altogether and switched/switching to ZTA/SASE, and for this, unlike in firewalls market for Fortigates, there is a lot of other vendors (Zscaler, Trend Micro, etc.) to choose from. 

    yurisk.info - all things Fortinet blog, no ads
    Toshi_Esumi
    SuperUser
    SuperUser
    July 4, 2026

    Most likely those customers would be forced to upgrade to newer versions when FTNT stops implementing some vulnerability fixes to 7.4 before the lifecycle ends. That’s what happened to all our FGTs to migrate from 7.2. Our customers demanded that.

    Toshi