FortiEndpoint
FortiEndpoint is a cloud based EMS solution hosted by Fortinet, built for new deployments. It combines FortiClient Cloud and FortiEDR, offering everything available in FortiClient Cloud with the added ability to deploy and manage FortiEDR collectors.
FortiClient Cloud handles the deployment and version management of collectors. When a deployment is created, a matching EDR collector group is automatically created. Endpoints added to the deployment are also added to this group.
In a standard EDR setup, version control is managed directly in the EDR console. With FortiEndpoint, this is done through the FortiClient installer settings. Collector group configuration stays within FortiClient Cloud, while policy and playbook management continues to be handled through the EDR console.
arleniscg
Staff
Staff
Article Id 415517
Description This article describes the initial assessments and considerations when installing FortiEndpoint for the first time, the features available on the packet install, and troubleshooting possible issues during this process.
Scope FortiEndpoint.
Solution
  1. Initial assessments and considerations:
  • If on the endpoint/PC  is already running a free/licensed FortiClient, uninstall it before running the FortiEndpoint install. 
  • If the PC has a FortiEDR collector from a previous service, uninstall it before running the FortiEndpoint install. Migration from FortiEDR to FortiEndpoint is not supported.
  • Validate that there is no active GPO from the old FortiClient/FortiEDR.
  • There is no .msi generated for the FortiEndpoint unified installer to use on a GPO deployment.
  • For initial deployment, the .exe installer can be used for manual installation on the endpoint or a GPO can be configured to run a script that executes the .exe installer 

 

  1.  Features available on the packet install. From the EMS-Server-Cloud, select:

  • FortiClient Installer name, required version,  OS, and invite.

 

endpoint 0.png

 

  • Customize required features and add FortiEDR.

 

endpoint 2.png


endpoint 3.png

 

  • Download the install, initial deployment can be: manual, GPO, MDM, or sending the link to the users. This will install FortiClient and FortiEDR on the endpoint/PC.

 

endpoint 5.png

 

endpoint 6.png

 

  1. Troubleshooting possible issues during this process: In case FortiEDR is installed on the Control Panel, but is disabled on the FortiClient GUI:

  • Validate endpoint is associated with a profile: System Settings that also has FortiEDR enabled: 

endpoint 7.png

 

  • If the issue is still present, open a case with Fortinet TAC Support Team. Gather and attach this information:

Open CMD as admin: 

 

Win:"C:\Program Files\Fortinet\FortiEDR\FortiEDRCollectorService.exe" --support

MacOs:sudo /Applications/FortiEDR.app/Contents/MacOS/FortiEDRCollector.app/Contents/MacOS/FortiEDRCollector --support

Linux:sudo /opt/FortiEDRCollector/bin/FortiEDRCollector --support

 

 

Set the client log level to debug in the FortiClient EMS profile, and provide the Diagnostic Tool output .cab file from the affected PC.

 

Path-Win: User\AppData\Local\FortiClient\tmp\Diagnostic_Result

Path-MacOS:cd /Library/Application\ Support/Fortinet/FortiClient/Logs