Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Holy
Contributor

FortiClient EMS 1.0.2 Blocking Teamviewer, Veem, Outlook as exploit

Hello everyone,

 

i have installed for a rist time the EMS and we are now Testing 20 Workstations with a customer. i must say EMS seems to be very cool improvment in comparison to managing FortiClient from FortiGate.

 

But we have one Big Issue now. 

 

We activated Application Control and Also Exploit Protection. and now a lot of "good" and well known Applications like Veem, Outlook, TeamViewer, Apple Mobile Device Service etc. will be blocked as Exploit or P2P (Veem Backup for example)

 

So the question is how can we override this Applications if they will be threated as Exploit???

 

Thank you very much.

 

 

NSE 8 

NSE 1 - 7

 

NSE 8 NSE 1 - 7
2 Solutions
Carl_Wallmark

From what I seen is that once you install the FortiClient it will popup alot of "blocked" messages.

and this is while it´s updating the signatures, once it´s done it works as expected.

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

View solution in original post

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
MikePruett

Yeah, I had FortiClient nuke team viewer etc while it was installing. After completion and proper compliance with the management device my stuff began working as it should.

View solution in original post

Mike Pruett Fortinet GURU | Fortinet Training Videos
10 REPLIES 10
SteveG
Contributor III

We're using EMS 1.0.2 in a production environment. TeamViewer is working fine on a test laptop I have access to. You sure there's not spyware on that machine?

 

Incidentally I'm also exporting the FortiClient logs to FortiAnalyzer, which is very helpful.

Holy

Hello,

 

yes i am sure and i tested it yeasterday in my lab environment and expirienced the same problems...

NSE 8 

NSE 1 - 7

 

NSE 8 NSE 1 - 7
SteveG
Contributor III

If it helps here are the version numbers I have installed.

 

Anti-Rootkit Engine2.00062AntiVirus Engine5.00233AntiVirus Signature39.00867AntiVirus Extended Signature39.00854AntiVirus Extreme Signature39.00854AntiVirus Heuristics Signature39.00867IPS Engine3.00154IPS Signature8.00971VCM Engine2.00015VCM Signature1.00116

 

Holy

hmm nothing Help.

 

is someone from Fortinet reading this? i also tried to reach my fortinet presale engineer but they do not have experience yet with EMS...

 

and i cannot open a ticket because we are now only in Test phase.

NSE 8 

NSE 1 - 7

 

NSE 8 NSE 1 - 7
SteveG
Contributor III

Ah ok. We do have a support contract so I raise calls via the Fortinet support portal.

Carl_Wallmark

From what I seen is that once you install the FortiClient it will popup alot of "blocked" messages.

and this is while it´s updating the signatures, once it´s done it works as expected.

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
MikePruett

Yeah, I had FortiClient nuke team viewer etc while it was installing. After completion and proper compliance with the management device my stuff began working as it should.

Mike Pruett Fortinet GURU | Fortinet Training Videos
Holy

 

 

Ohh i see, i will Test next week.

 

Yes this Messages came right after Install. 

 

Thanks for info

NSE 8 

NSE 1 - 7

 

NSE 8 NSE 1 - 7
Arne_Vanderheyden
New Contributor

Have you worked this out? I tried to deploy the Application FW too, but from what it's blocking by default sortof utterly worthless.

The EMS interface 'add signatures' button doesn't even do anything on my installs...

Labels
Top Kudoed Authors