I am in the process of implementing and testing FortiClient which is being managed by EMS. The web filtering options in EMS are not a feature rich as the Fortigate. I do have another on-premise web filtering solution that I use to filter on and off network (via proxy) and investigating my options now with the FortiClient. My question is, can I provision my clients with EMS but somehow utilize the Fortigate for webfiltering (main focus is while off network) since it does have more web filter functionality?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
azh wrote:Hello,
You can use FortiGate for compliance check and enable there "Security Posture Check" to use FortiGate Security Profiles for FortiClient. You will centrally manage via FortiEMS and do other security things on FortiGate.
Here is example - http://cookbook.fortinet.com/enforcing-network-security-forticlient-profile-54/
But this is just for while on-net. What I am after is seeing if there is a way to get the Fortigate to be the web filter (since it has better web filter features) instead of the EMS while off-net. I know I can VPN in, thus putting me on-net, but I am looking to do this with over 3000 users. Having over 3000 users VPN is not really something I want to get into.
In order for the Fortigate to filter EMS Client traffic, it needs to be in the traffic flow.
VPN is the normal way to accomplish this.
Which aspect of web filter do you prefer on the Fortigate?
SteveRoadWarrior wrote:The other biggies for me is the "Search Engine" section and to a smaller degree, the "Proxy Options" section. Since I am a K-12 school, being able to safe search search engines, restrict YouTube, and log all keyword searches is huge. We tie into Google, so restricting accounts to specific Google domain is something I am used to being able to do now with my current filter. I was kind of hoping that EMS had those features for macOS/Windows like they currently do for Chromebook or that I could use the FortiClient to proxy back to my Fortigate, thus replacing my current web-filter.In order for the Fortigate to filter EMS Client traffic, it needs to be in the traffic flow.
VPN is the normal way to accomplish this.
Which aspect of web filter do you prefer on the Fortigate?
Google Safe Search, Youtube Play and Google Search are all available from the application firewall feature of EMS/FortiClient.
Haven't tested it out to see if it would log the search words but worth trying out.
*edit* Just tested it out and the google safe search through the app control doesn't seem to work with Firefox or Chrome so scratch that idea.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1502 | |
1011 | |
749 | |
443 | |
209 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.