Skip to main content
vinceneil666
New Member
May 3, 2018
Solved

Fortinet EMS design

  • May 3, 2018
  • 6 replies
  • 14723 views

Hi,

 

Where do you guys place your EMS server ? From a security point of view I'm considering placing it on a dmz that I can make available for our clients (multi customer enviroment). And just put in some rules.... But it might be even better having it behind an F5 service or something other ? 

 

Any inputs ? tips ? :)

    Best answer by ergotherego

    We put ours in a DMZ, and use a directly-assigned public IP address to avoid any DNS split-horizon issues.

     

    Permitting TCP-8013 inbound from the world, geofenced to NA, with UTM applied. We didn't start off permitting inbound from the Internet, and were initially restricting to on-net sources only. But it caused too many issues for remote clients so we opened it up.

    6 replies

    ergotherego
    New Member
    May 3, 2018

    We put ours in a DMZ, and use a directly-assigned public IP address to avoid any DNS split-horizon issues.

     

    Permitting TCP-8013 inbound from the world, geofenced to NA, with UTM applied. We didn't start off permitting inbound from the Internet, and were initially restricting to on-net sources only. But it caused too many issues for remote clients so we opened it up.

    SteveG
    New Member
    May 3, 2018

    Great question as I've recently been caught out by this! Here's what I've done. Originally access from the FortiClients to EMS was only available when 'on prem' or VPN'd in. This worked fine to begin with but more and more staff are working remotely and not VPNing as we're a GSuite organisation but I still wanted the ability to push FC config changes etc. This required me to redesign our EMS install. I wanted to expose it externally but when original rolled out I hadn't configure the 'FortiClient telemetry connection key' which is needed to stop unathorised FC's registering. 

     

    If starting fresh I'd suggest you:

    Give the EMS server an external name, ideally have the FQDN resolve to the internal IP when on the internal network to save unnecessary firewall traffic.

    Enable the Connection Key!

     

    We have a pair of FortiADC's so our EMS server is exposed to the internet via the ADC DMZ network. 

    Externally is resolves to x.x.x.x Ports 8013 & 8014 are open to our specific country.

    Password (Forticlient Connection Key) is a little more tricky. But here's the process to achieve if you've rolled out without one.

  • Create a Gateway List for ems.company.com that includes a Connection Key.
  • Apply this new Gateway list to all existing profiles that are applied to clients.
  • Clients receive new Gateway list that includes the Connection key.
  • Within the EMS GUI "system settings", "Endpoints" configure a Connection Key that matches the one used in the Gateway List.
  • Doing these things in this order means the FortiClients remain registered to EMS without the need to enter the key.
  • Should someone need to connect that hasn't previously registered then they will be prompted to enter the Connection Key (make sure the tick both save boxes).[/ul]
  • Markus
    New Member
    May 3, 2018

    Good point, we put ours also in a DMZ and we have a quite similar setup. Important is the Connection Key.

    vinceneil666
    New Member
    May 4, 2018

    This is great feedback guys, made my day - I will be sure to share my final design on this when done. 

    bbrown
    New Member
    May 23, 2018

    We built an EMS network and have the EMS server behind a FGT 60E.

    We then build out StoS VPNs from the customer's routers to ours.

    For offnet customers we have allowed ports 8113 and 8114 to the EMS server.

     

    Keep it simple. Keep it secure.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!