FortiClient
FortiClient proactively defends against advanced attacks. Its tight integration with the Security Fabric enables policy-based automation to contain threats and control outbreaks. FortiClient is compatible with Fabric-Ready partners to further strengthen enterprises’ security posture.
ika
Staff
Staff
Article Id 353417
Description

This article describes how to automatically allocate endpoints to custom groups in Workgroups.

Any endpoints that do not meet any of the group assignment rules will be automatically placed in the Other Endpoints group.

This rule does not apply to domain-joined endpoints, even if it matches a previously created group assignment rule.

Scope EMS (on-prem and Cloud)
Solution

There are four types of group assignment rules, which can be distinguished by:

  • Installer ID
  • Invitation
  • IP Address
  • OS

 

  1. Installer ID
  • Create an installer ID group assignment rule and select the desired group to allocate the endpoint that deployed using the FortiClient Installer that was packaged from EMS.

rule_installerID.png

 

  • Create a FortiClient Installer deployment package and include the created Installer ID.

 

installerID.png

 

  • Any FortiClient endpoint that was installed using this installer package will automatically be placed in the defined group. In this example, the HR Dept group.

 

  1. Invitation.
  • Create an invitation code under the Endpoints -> Invitations tab.

 

InvitationCode.PNG

 

  • Create a group assignment rule under the Endpoints -> Group Assignment Rules tab to select the created invitation code and desired group.

 

rule_invitation.png

 

  • Any FortiClient endpoint that is connected to the EMS using this invitation code will be placed automatically in the defined group. In this example, the Sales Dept group.

 

  1. IP Address
  • Create an IP Address group assignment rule under the Endpoints -> Group Assignment Rules tab and enter a specific IPv4 subnet/IP range. IPv6 subnet/IP range is not supported.
  • Select the desired group to allocate the endpoint that matched the defined IP address in the next telemetry communication.

 

rule_IPAddress.png

 

  1. OS.
  • Create an OS group assignment rule under the Endpoints -> Group Assignment Rules tab and enter specific OS, for example Windows/Windows Server 2019.
  • Select the desired group to allocate the endpoint that matched the defined OS in the next telemetry communication.

 

rule_OS.PNG

 

Contributors