Skip to main content
AEK
SuperUser
SuperUser
October 21, 2025
Solved

FortiClient EMS installation modes

  • October 21, 2025
  • 9 replies
  • 1688 views

Hi EMS admins

Starting from 7.4.4, in addition to the EMS binary installation method on Linux VM, Fortinet introduced a new installation mode which is VM image: a customized/hardened Linux with pre-installed EMS software, where we can't access the Linux shell, and only the new EMS shell is available.

My questions are:

  1. As there are now 2 installation modes, is there one specific mode that is recommended?
  2. As this is the first release with the VM image install mode, is it recommended to install it in production? I mean is it enough stable? Will I find all the commands I need for all kinds of configuration and troubleshooting that I may need? E.g.: Can I check OS and DB log files? Can run tcpdump or similar sniffer command for traffic troubleshooting?
  3. I guess the standalone installation mode (with binary file) will be discontinued and the VM image install will be the unique available mode, right? So if I have now a standalone installation in my current prod and want to anticipate by moving to VM image mode, is there an available conversion method? Or should I proceed with a migration?
Best answer by MZBZ

Hello @AEK 

1. The new EMS Appliance 7.4.4 is part of the previous EMS VM 7.4.3. Neither one is recommended and selection is merely based on the project requirement and admin experience/knowledge of Linux OS.

2. As I mentioned, this is a continuation of the previous 7.4.3 VM image. EMSCLI tool has been improved to provide more OS-related control in 7.4.5 (which can also be added to 7.4.4 via hotfix id 1200663)

3. EMS DB backup-restore works on any EMS setup as long as the version matches. Starting from 7.4.5 we will support restoring a DB from older EMS 7.4 version as well! You can easily restore a backup from an EMS appliance to a standalone EMS or a complex EMS HA cluster. I cannot comment on the future path for EMS release structure; however, considering requirements for complex HA setups, the binary file will most probably be available in the futrure.

Hopefully these provide answer to your questions.

9 replies

Anthony_E
Staff
Staff
October 24, 2025

Hello Abdlekrim,

I hope you are doing well.


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Best Regards
AEK
SuperUser
AEKAuthor
SuperUser
October 26, 2025

Hi Anthony

Thanks for your message and for handling my request.

AEK
Anthony_E
Staff
Staff
October 29, 2025

Hello Abdelkrim,

 

Sorry, we are still looking for someone to help you.

We will come back to you ASAP.


Thanks

Best Regards
AEK
SuperUser
AEKAuthor
SuperUser
October 29, 2025

Thanks again Anthony. I appreciate.

AEK
MZBZ
Staff
MZBZAnswer
Staff
October 30, 2025

Hello @AEK 

1. The new EMS Appliance 7.4.4 is part of the previous EMS VM 7.4.3. Neither one is recommended and selection is merely based on the project requirement and admin experience/knowledge of Linux OS.

2. As I mentioned, this is a continuation of the previous 7.4.3 VM image. EMSCLI tool has been improved to provide more OS-related control in 7.4.5 (which can also be added to 7.4.4 via hotfix id 1200663)

3. EMS DB backup-restore works on any EMS setup as long as the version matches. Starting from 7.4.5 we will support restoring a DB from older EMS 7.4 version as well! You can easily restore a backup from an EMS appliance to a standalone EMS or a complex EMS HA cluster. I cannot comment on the future path for EMS release structure; however, considering requirements for complex HA setups, the binary file will most probably be available in the futrure.

Hopefully these provide answer to your questions.

AEK
SuperUser
AEKAuthor
SuperUser
October 30, 2025

Hi MB

Thanks for the information. All is much clearer now.

AEK
AEK
SuperUser
AEKAuthor
SuperUser
December 13, 2025

Hello @MZBZ 

Now as EMS 7.4.5 is released, I'm searching in the new features and CLI ref but can't find how to access to more OS commands.

My main concern so far is tcpdump and NTP configuration.

Any useful info would be appreciated.

AEK
MZBZ
Staff
Staff
December 15, 2025

Docs will be updated in the upcoming days...

AEK
SuperUser
AEKAuthor
SuperUser
December 15, 2025

I know when marketing team has a target then the product is released even if the docs is are not ready yet ;)

AEK
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!