I did FortiEMS deployment and installed Forticlient for 1000 machines. After I did Vulnerability scanning im got some Vul with Auto and others as manual.
My question is, how can I do manual patching through EMS? Is there a way to install the patch from the internet manually and upload the MSI or patch file to EMS to push it automatically to all machines? OR does manual patching mean that users have to do it by themselves only?
In addition, can I create a custom message to show to users once they log in to their machines including a message and link to download the patch of vulnerability manually?
#ems #vulnerability #patch
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello,
FortiClient's vulnerability patching can only patch applications that can be tasked with patching.
FortiClient itself does not perform the patching, rather, it tasks the Application to contact its own update server to download and update itself.
If the Application cannot be tasked, FortiClient will display that the patching requires manual patching.
If an Application is auto-patched and requires a reboot to complete its action, this is relayed to the FortiClient which in turn relays it to the user.
In all of this, FortiClient's role is that of a conductor; it only directs the required actions needed to the Application.
If patching is needed to a certain level (ie. critical), FortiClient searches the Vulnerability list for all critical Vulnerabilities, and then searches for installed Applications matching the vulnerability list; each Application is then tasked to perform its own update as required.
Please see here for more information on the vulnerability scan feature- https://docs.fortinet.com/document/forticlient/7.2.2/ems-administration-guide/202270/vulnerability-s...
Hope this helps :)
Hello osaleem2_10,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Hello,
We are still looking for someone to help you.
We will come back to you ASAP.
Regards,
1. Manual mean its intended to be done manually by administrator. Ems cannot push sw payload to endpoints
2. I think Yes but not via EMS.
Hello,
FortiClient's vulnerability patching can only patch applications that can be tasked with patching.
FortiClient itself does not perform the patching, rather, it tasks the Application to contact its own update server to download and update itself.
If the Application cannot be tasked, FortiClient will display that the patching requires manual patching.
If an Application is auto-patched and requires a reboot to complete its action, this is relayed to the FortiClient which in turn relays it to the user.
In all of this, FortiClient's role is that of a conductor; it only directs the required actions needed to the Application.
If patching is needed to a certain level (ie. critical), FortiClient searches the Vulnerability list for all critical Vulnerabilities, and then searches for installed Applications matching the vulnerability list; each Application is then tasked to perform its own update as required.
Please see here for more information on the vulnerability scan feature- https://docs.fortinet.com/document/forticlient/7.2.2/ems-administration-guide/202270/vulnerability-s...
Hope this helps :)
thanks Blkktivity.
appreciate your explanation.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1705 | |
1093 | |
752 | |
446 | |
230 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.