Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
osaleem2_10
New Contributor II

EMS Manual patch

I did FortiEMS deployment and installed Forticlient for 1000 machines. After I did Vulnerability scanning im got some Vul with Auto and others as manual.

 

My question is, how can I do manual patching through EMS? Is there a way to install the patch from the internet manually and upload the MSI or patch file to EMS to push it automatically to all machines? OR does manual patching mean that users have to do it by themselves only?

In addition, can I create a custom message to show to users once they log in to their machines including a message and link to download the patch of vulnerability manually?

 

#ems #vulnerability #patch

OSALEEM2_10
OSALEEM2_10
1 Solution
Blkktivity
Staff
Staff

Hello,

 

FortiClient's vulnerability patching can only patch applications that can be tasked with patching.
FortiClient itself does not perform the patching, rather, it tasks the Application to contact its own update server to download and update itself.
If the Application cannot be tasked, FortiClient will display that the patching requires manual patching.
If an Application is auto-patched and requires a reboot to complete its action, this is relayed to the FortiClient which in turn relays it to the user.
In all of this, FortiClient's role is that of a conductor; it only directs the required actions needed to the Application.
If patching is needed to a certain level (ie. critical), FortiClient searches the Vulnerability list for all critical Vulnerabilities, and then searches for installed Applications matching the vulnerability list; each Application is then tasked to perform its own update as required.

Please see here for more information on the vulnerability scan feature- https://docs.fortinet.com/document/forticlient/7.2.2/ems-administration-guide/202270/vulnerability-s...

 

Hope this helps :)

View solution in original post

5 REPLIES 5
Stephen_G
Moderator
Moderator

Hello osaleem2_10,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Stephen - Fortinet Community Team
Stephen_G
Moderator
Moderator

Hello,

 

We are still looking for someone to help you.

We will come back to you ASAP.


Regards,

Stephen - Fortinet Community Team
peisenberg
Staff
Staff

1. Manual mean its intended to be done manually by administrator. Ems cannot push sw payload to endpoints 

2. I think Yes but not via EMS. 

TAC
Blkktivity
Staff
Staff

Hello,

 

FortiClient's vulnerability patching can only patch applications that can be tasked with patching.
FortiClient itself does not perform the patching, rather, it tasks the Application to contact its own update server to download and update itself.
If the Application cannot be tasked, FortiClient will display that the patching requires manual patching.
If an Application is auto-patched and requires a reboot to complete its action, this is relayed to the FortiClient which in turn relays it to the user.
In all of this, FortiClient's role is that of a conductor; it only directs the required actions needed to the Application.
If patching is needed to a certain level (ie. critical), FortiClient searches the Vulnerability list for all critical Vulnerabilities, and then searches for installed Applications matching the vulnerability list; each Application is then tasked to perform its own update as required.

Please see here for more information on the vulnerability scan feature- https://docs.fortinet.com/document/forticlient/7.2.2/ems-administration-guide/202270/vulnerability-s...

 

Hope this helps :)

osaleem2_10
New Contributor II

thanks Blkktivity. 

 

appreciate your explanation.

OSALEEM2_10
OSALEEM2_10
Top Kudoed Authors