Hello Team,
I am deploying forticlient EMS and stuck at few things and would appreciate if some one guide:
1. I had installed the forticlient EMS and created a remote VPN profile. This profile is pushed once the remote laptop is connected with the forticlient EMS.
2. Lets say a user is working from home and I need to pushed the VPN profile on his laptop, if its not pushed, a user will not be able to connect to the VPN. So what will be work out of this, how a remote user gets connected to the EMS server and how this all will work?
3. Also if there are two ISPs (Internet Service Provider) running, and we want to connect the remote users on both of them. Then what configurations we need to do on the forigate firewall and on the Forticlient EMS?
Appreciate if someone could help on this.
Thanks
Hello
kindly advise first of the integration between the EMS and the FortiGate is already established, also you need to set up the same vpn configuration on the FortiGate as well. please ensure that the FortiClient Endpoint is tagged with the correct zero trust tag, once all these steps are completed, you should have the configuration pushed automatically to the endpoint without any user intervention. Also you can use the zero trust tag to always verify the user compliance status and drop the user vpn connection once the TAG become unverified.
For the ISP back up on both links you can use the BGP configuration if it is feasible or do the confiugration failove using floating static route with link-monitor to failover to the backup link whenever the primary link is down and to recover to the primary link when it is up again.
please let me know if this can help you or if you want any additional help
regards
Michel Makhoul
Hi,
Thanks for your reply.
The integration between EMS and Fortigate is already done.
Basically I had created a remote access vpn on the fortigate and ipsec tunnel profile on the Forticlient EMS.
hi
is the endpoint tagged correctly and endpoint to EMS connector is up?
ur welcome dear
Well we didn't configure any ZTNA tag right now (I thought of doing this once the remote VPN connection gets successful for all type of users i.e. on-prem and remote users working from home).
What we did is configure the basic settings of FortiClient EMS, create a Remote access IPSec VPN profile and then go the manager deployments and start the scheduling.
After that through the invitation code, we connect the forticlient with the EMS. The devices which are on the same network have the Remote access VPN configuration pushed.
But how it will be done for the users that are working from the home.
Can you please guide what are the missing steps and what needs to be done for this to work smoothly.
You can share an URL with the users, so they can download and execute the first installation package of FortiClient, which you can customize to be installed with the proper VPN configuration.
Check KB https://community.fortinet.com/t5/FortiClient/Technical-Tip-How-to-change-FortiClient-download-and-m... for details.
To have the users connecting to both IPSs, you can do it by DNS. Basically you need to advertise that the fqdn of your vpn gateway can be resolved to either one of your ISP addresses.
Also,
Anyone can help?
You can also use the EMS Invitations to share the installer and invite the users to join EMS:
Allright, The Forticlient is not able to connect with the EMS through EMS server IP. When we asked for the IP, its requesting for the invitation code, whereas we want to only connect this via EMS server IP.
What will be the workout of this?
Hi muhammadsaad,
The first thing to effectively use EMS is to publish your EMS to Internet (so that the telemetry can be reached from Internet (user working from home, not in office network). I have attached a quick sample guide pdf file. At the very least, allow port 8013 and 10443 from Internet to reach your EMS server.
Next, if right now there is no machine that can join to your EMS using IP (even using an private/internal IP), please check below:
-> Go to EMS -> System Settings, ensure that [Enforce User Verification] is unticked and [Enforce invitation-only registration for] is set to NONE.
 
					
				
				
			
		
| User | Count | 
|---|---|
| 2648 | |
| 1405 | |
| 810 | |
| 690 | |
| 455 | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.