Description | This article describes how to prevent a FortiClient EMS connector from being applied to all FortiGates in an ADOM. |
Scope | FortiManager. |
Solution |
In FortiManager, once a FortiClient EMS fabric connector is defined within an ADOM, it is automatically pushed to all FortiGate devices managed under that ADOM. To prevent the EMS connector from being applied to FortiGate devices where it is not required, a custom CLI template can be used. This template will override the EMS connector configuration, effectively disabling it on specific FortiGates.
Workaround Steps:
Example CLI commands:
config endpoint-control fctems
edit "1" unset name unset server set status disable next end
While FortiManager currently does not provide a built-in option to limit EMS connector deployment to selected FortiGates within an ADOM, this can be effectively managed through the use of CLI templates. This method ensures that only the required devices maintain the EMS connector configuration, maintaining proper segmentation and reducing unnecessary configurations on non-participating FortiGates. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.