Skip to main content
Polar
New Member
March 27, 2020
Question

Fresh FortiClient install on VM 2012R2. Don't understand how to do remote install. Help?

  • March 27, 2020
  • 4 replies
  • 5715 views

Hi all,

 

This is my first post here. I have been using AVG Internet Security Business Edition, with Remote Administration. While the software itself is easy to manage when it is installed, I find it cumbersome to deploy with Remote Administration on the PC's. Sometimes it works just fine, some times I just give up and need to install it locally. Newly the need for VPN to remote locations announced itself, and am not convinced this will work out of the box on a LAN with a workgroup + VPN.

 

Currently I am testing Forticlient. My goal is to have a Windows 2012 R2 with FortiClient EMS, and have the possibility to remote install and manage all clients/PCs on the network.

 

The first question that popped up here was: Do I need a Active Directory Server to achieve Remote Client Management?

 

Since I couldn't find the answer to this I just went ahead and installed the AD and DNS. Domain is up and running and FC EMS sees the domain. I have also a VM Win7 box that I added to the domain. The user is created on AD, and I can logon from the Win7 VM to the domain. I only created the user with default settings, no profiles, nothing else.

 

In FC EMS > Endpoints I see the Win2012R2 Server, and the Win7 PC. An interesting detail is that the endpoints are listed with no user, no IP, default policy (see attached Endpoints.jpg).

 

Where do I take it from here? Many thanks for reading this.

 

 

    4 replies

    FortinKnight
    New Member
    April 16, 2020

    i would presume that you need to install the forticlient onto the windows 7 machine, either by pushing it from the EMS server to the client or by installing forticlient directly on the client and than pointing it back to the EMS server.

     

    if you click on the win7 entry in your screenshot, it should expand out and show you more information concerning the state of the machine.

     

     

    Polar
    PolarAuthor
    New Member
    April 18, 2020

    Thank you @FortinKnight for your input. Indeed, I get all this information when clicking on the Win7 entry. Here it says, not managed by EMS, nothing installed, etc. So the question is, how do I push it from the server to Win7 PC?

    joe_FTNT
    Staff
    Staff
    April 18, 2020

    Please see the FortiClient EMS Administration Guide.

    https://docs.fortinet.com/document/forticlient/6.2.6/ems-administration-guide/24450/introduction

     

    See the sections on:

     

    Preparing Active Directory (There are Group Policies that must be set in advance to allow remote installation and make sure that Windows Firewall ports are configured)

    https://docs.fortinet.com/document/forticlient/6.2.6/ems-administration-guide/978154/preparing-the-ad-server-for-deployment

     

    Managing Installers:

    https://docs.fortinet.com/document/forticlient/6.2.6/ems-administration-guide/420720/managing-installers

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!