FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
martinsd
Staff
Staff
Article Id 262499
Description This article describes an important caveat with a setup involving a FortiGate and FortiClient EMS Connector on a Multi-VDOM with a VDOM Partitioning environment.
Scope FortiGate v7.4.0 or below.
Solution

To use TAGs for ZTNA traffic on a VDOM with VDOM Partitioning in v7.4.0 or below, it is necessary to ensure that the VDOM that implements the TAG is on the same partition (same virtual cluster) as the management VDOM. Otherwise, the VDOM will not be able to retrieve TAG information from FortiClient EMS.

 

If the FortiGate is running v7.2.x and earlier firmware versions and has enabled multi-vdom, it is not possible to configure FortiClient EMS and FortiClient EMS Cloud on other VDOMs rather than Global VDOM. Enabling override under 'endpoint-control' settings via CLI is not an option :

 

PIC6.png

 

v7.4.0 introduced a new feature that allows for the configuration of FortiClient EMS and FortiClient EMS Cloud on a per-VDOM basis.

There are some pre-requisites:

  • V7.4.x and 7.6.x and later.
  • Override should be configured for each VDOM that connects to an EMS server.
  • FortiClient EMS v7.2.1 and later

 

Override can be enabled under endpoint-control settings as per the following:

 

config endpoint-control settings
    set override {enable | disable}
end

 

PIC7.png

 

See the 'configuring FortiClient EMS and FortiClient EMS Cloud on a per-VDOM basis' section in the FortiGate... for more information.