Created on
09-30-2025
09:16 AM
Edited on
09-30-2025
10:10 PM
By
Anthony_E
This article explains how to enable FortiClient EMS Serial Number check on FortiGate before allowing to establish a VPN connection. This feature enhances VPN security on FortiGate by only allowing VPN connection requests from the FortiClient's which are managed by a FortiClient EMS connected to FortiGate via Security Fabric all other VPN connection requests are denied.
FortiGate, FortiClient EMS, FortiClient Windows, FortiClient MacOS, FortiClient Linux.
Requirements:
config system global
set vpn-ems-sn-check {enable | disable}
end
config vpn ipsec phase1-interface
edit <phase1-name>
set ems-sn-check {enable | disable}
end
config system global
set vpn-ems-sn-check {enable | disable}
end
config vpn ipsec phase1-interface
edit <phase1-name>
set ems-sn-check {enable | disable}
end
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.