Skip to main content
muhammadsaad
New Member
June 18, 2025
Question

FortiClient EMS | Assistance Required

  • June 18, 2025
  • 14 replies
  • 3570 views

Hello Team,

I am deploying forticlient EMS and stuck at few things and would appreciate if some one guide:

1. I had installed the forticlient EMS and created a remote VPN profile. This profile is pushed once the remote laptop is connected with the forticlient EMS.

2. Lets say a user is working from home and I need to pushed the VPN profile on his laptop, if its not pushed, a user will not be able to connect to the VPN. So what will be work out of this, how a remote user gets connected to the EMS server and how this all will work?
3. Also if there are two ISPs (Internet Service Provider) running, and we want to connect the remote users on both of them. Then what configurations we need to do on the forigate firewall and on the Forticlient EMS?

 

Appreciate if someone could help on this.

Thanks

14 replies

Michel-Makhoul
New Member
June 18, 2025

Hello

 

kindly advise first of the integration between the EMS and the FortiGate is already established, also you need to set up the same vpn configuration on the FortiGate as well. please ensure that the FortiClient Endpoint is tagged with the correct zero trust tag, once all these steps are completed, you should have the configuration pushed automatically to the endpoint without any user intervention. Also you can use the zero trust tag to always verify the user compliance status and drop the user vpn connection once the TAG become unverified.

For the ISP back up on both links you  can use the BGP configuration if it is feasible or do the confiugration failove using floating static route with link-monitor to failover to the backup link whenever the primary link is down and to recover to the primary link when it is up again.

 

please let me know if this can help you or if you want any additional help

 

regards

Michel Makhoul

muhammadsaad
New Member
June 18, 2025

Hi,

Thanks for your reply.

The integration between EMS and Fortigate is already done.
Basically I had created a remote access vpn on the fortigate and ipsec tunnel profile on the Forticlient EMS.

Michel-Makhoul
New Member
June 18, 2025

hi

 

is the endpoint tagged correctly and endpoint to EMS connector is up?

 

ur welcome dear

 

muhammadsaad
New Member
June 18, 2025

Anyone can help?

ebrlima
Staff
Staff
June 18, 2025

You can also use the EMS Invitations to share the installer and invite the users to join EMS:

 

https://docs.fortinet.com/document/forticlient/7.4.0/onboarding-for-ztna-deployment-guide/688483/inviting-users-to-join-ems

muhammadsaad
New Member
June 19, 2025

Allright, The Forticlient is not able to connect with the EMS through EMS server IP. When we asked for the IP, its requesting for the invitation code, whereas we want to only connect this via EMS server IP.

What will be the workout of this?

btan
Staff & Editor
Staff & Editor
June 19, 2025

Hi @muhammadsaad,

 

The first thing to effectively use EMS is to publish your EMS to Internet (so that the telemetry can be reached from Internet (user working from home, not in office network). I have attached a quick sample guide pdf file. At the very least, allow port 8013 and 10443 from Internet to reach your EMS server.

Next, if right now there is no machine that can join to your EMS using IP (even using an private/internal IP), please check below:
-> Go to EMS -> System Settings, ensure that [Enforce User Verification] is unticked and [Enforce invitation-only registration for] is set to NONE.
enforce-none.png

muhammadsaad
New Member
June 19, 2025

All right thanks,

We are stuck at one point now. We have installed Forticlient EMS 7.4.1 and when we try to use Forticlient installer 7.4.3 and sending the invite to a user, its not working. So now i need to upgrade my Forticlient EMS from 7.4.1 to 7.4.3.

Can someone help out and share the procedure.

Many thanks

btan
Staff & Editor
Staff & Editor
June 20, 2025

Hi muhammadsaad, "invite to a user, its not working" --> this should not related to EMS version. You have to check if your SMTP server is configured correctly.

On a sidenote, EMS upgrade procedure is described clearly here:
https://docs.fortinet.com/document/forticlient/7.4.3/ems-administration-guide/880046/upgrading-from-an-earlier-forticlient-ems-version

 

muhammadsaad
New Member
June 20, 2025

Hi, Thanks for your reply

Basically, the forticlient installer configuration is not getting pushed on the invite. When we troubleshoot it was identified that we are using forticlient version 7.4.3 and EMS version is 7.4.1.

 

Furthermore, we have routed the EMS server publicly but its not connecting at the Forticlient when we right the public IP at below:

ems1.png

We are basically doing this before connecting to the remote VPN.

 

Can some one also help out and share the traffic flow of remote VPN users connecting to the Fortigate and Forticlient EMS. Like what's will be connected first, Fortigate remote VPN or Forticlient EMS.

 

Many thanks for helping out

Cheers

btan
Staff & Editor
Staff & Editor
June 20, 2025

Your screenshot looks like it is a FortiClient 6.4.x version, or even older.


I would suggest you to raise a FortiCare ticket to so that TAC engineer can clarify to you further on EMS/FCT general concept.

muhammadsaad
New Member
June 20, 2025

Well we are doing it on the Forticlient version 7.4.3 as well, but its connecting from the Public IP.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!