Skip to main content
AEK
SuperUser
SuperUser
September 26, 2024
Question

FortiPAM Web launcher from WAN

  • September 26, 2024
  • 11 replies
  • 5316 views

Hello PAM admins

FortiPAM 1.4.1.

I'm very new in FortiPAM and I have questions regarding Web launcher.

When I'm in company's local network all works fine, Web launcher, RDP launcher and SSH launcher.

However when I'm outside and connect from public IP and try run Web launcher it doesn't work, while SSH launcher and RDP launcher still work fine.

I noticed that for both RDP and SSH launcher, PAM opens the browser tab with address bar contains a public address like https://pam.mycompany.com/someaddress.

While for Web launcher it opens the private IP of the target, which naturally can't work from WAN without some proxy on the client.

If I'm not wrong I think it needs FortiClient in order to work, right?

So my question:

  • Does it work with FortiClient for Windows, Linux & MacOS?
  • Does it require EMS?
  • Is there a plan to make it work in future release without FortiClient? (other PAM products can do it without agent)

11 replies

Anthony_E
Staff
Staff
September 30, 2024

Hello Abdelkrim,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Best Regards
Anthony_E
Staff
Staff
October 2, 2024

Hello Abdelkrim,

 

We are still looking for someone to help you.

We will come back to you ASAP.


Regards,

Best Regards
AEK
SuperUser
AEKAuthor
SuperUser
October 2, 2024

Thanks Antony for your support

Nothing urgent for now.

AEK
Anthony_E
Staff
Staff
October 2, 2024

Thank you Abdelkrim :)!

Best Regards
chrisbenny
New Member
October 2, 2024

Hi,

In the target of the secret under advanced settings, have you enabled "Web proxy" and "Domain list" with access mode as "proxy" and then set up a FQDN or IP list?

https://docs.fortinet.com/document/fortipam/1.4.0/examples/699270/configuring-the-web-proxy-feature-to-prevent-web-credentials-from-leaking

https://docs.fortinet.com/document/fortipam/1.4.1/administration-guide/460943/web-proxy 

AEK
SuperUser
AEKAuthor
SuperUser
October 5, 2024

Hi Chris

Thanks for your response.

I'll try this method and comeback with the result.

AEK
DylanFox
New Member
October 11, 2024

Any update?

KIMAN_NGOR
New Member
November 7, 2024

Hello Abdelkrim,

 

Here are some steps to troubleshooting:

1. Ensure that FortiPAM can access to the internal web portal, if case FQDN ,FortiPAM can resolve .

2. Make sure you have enabled web proxy on the interface. https://docs.fortinet.com/document/fortipam/1.4.0/examples/390911/enabling-the-web-proxy-feature

3. Create secret target & enable Web Proxy . https://docs.fortinet.com/document/fortipam/1.4.0/examples/2487/creating-a-secret-target-with-web-proxy

4. Add a secret target to your secret.

5. if FortiPAM is behind the FortiGate or other firewall vendor . https://docs.fortinet.com/document/fortipam/1.4.0/examples/168674/fortipam-behind-a-fortigate-device

6. Create DNAT on the firewall and allow all ports , do not specify only FortiPAM's port (FortiPAM's portal) .

 

Thanks,

pjaco
Explorer
May 19, 2025

Hi,

we have same problem in our environment. One question to your troubleshooting guide. Number 6 - why? Why do I have to forward all ports from external IP to FortiPAM? Customer doesn't have much free external IP addresses, we are sharing one address with multiple services. One of them is FortiPAM portal. Is it really necessary? Or could you specify which ports are needed? (except 443). Thank you.

AEK
SuperUser
AEKAuthor
SuperUser
August 11, 2026

This post is old but for those who may be interested here is what we found,

To properly use Web launcher from WAN (or even from LAN) you need to install FortiClient PAM, otherwise your client will try reach directly the private address of the backend Web server (bypassing PAM).

Initially this was not obvious for me at all since other known PAM solutions don’t need any proxy component to be installed on the client.

Now in case you access the PAM through VPN (IPsec or SSL) then know that you need FortiClient commercial version, since FortiClient VPN cannot cohabit with FortiClient PAM.

AEK
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!