Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
muhammadsaad
Contributor

FortiClient EMS | Assistance Required

Hello Team,

I am deploying forticlient EMS and stuck at few things and would appreciate if some one guide:

1. I had installed the forticlient EMS and created a remote VPN profile. This profile is pushed once the remote laptop is connected with the forticlient EMS.

2. Lets say a user is working from home and I need to pushed the VPN profile on his laptop, if its not pushed, a user will not be able to connect to the VPN. So what will be work out of this, how a remote user gets connected to the EMS server and how this all will work?
3. Also if there are two ISPs (Internet Service Provider) running, and we want to connect the remote users on both of them. Then what configurations we need to do on the forigate firewall and on the Forticlient EMS?

 

Appreciate if someone could help on this.

Thanks

14 REPLIES 14
Michel-Makhoul
New Contributor

Hello

 

kindly advise first of the integration between the EMS and the FortiGate is already established, also you need to set up the same vpn configuration on the FortiGate as well. please ensure that the FortiClient Endpoint is tagged with the correct zero trust tag, once all these steps are completed, you should have the configuration pushed automatically to the endpoint without any user intervention. Also you can use the zero trust tag to always verify the user compliance status and drop the user vpn connection once the TAG become unverified.

For the ISP back up on both links you  can use the BGP configuration if it is feasible or do the confiugration failove using floating static route with link-monitor to failover to the backup link whenever the primary link is down and to recover to the primary link when it is up again.

 

please let me know if this can help you or if you want any additional help

 

regards

Michel Makhoul

muhammadsaad

Hi,

Thanks for your reply.

The integration between EMS and Fortigate is already done.
Basically I had created a remote access vpn on the fortigate and ipsec tunnel profile on the Forticlient EMS.

Michel-Makhoul

hi

 

is the endpoint tagged correctly and endpoint to EMS connector is up?

 

ur welcome dear

 

muhammadsaad

Well we didn't configure any ZTNA tag right now (I thought of doing this once the remote VPN connection gets successful for all type of users i.e. on-prem and remote users working from home).

 

What we did is configure the basic settings of FortiClient EMS, create a Remote access IPSec VPN profile and then go the manager deployments and start the scheduling.

After that through the invitation code, we connect the forticlient with the EMS. The devices which are on the same network have the Remote access VPN configuration pushed.
But how it will be done for the users that are working from the home.

Can you please guide what are the missing steps and what needs to be done for this to work smoothly.

ebrlima

You can share an URL with the users, so they can download and execute the first installation package of FortiClient, which you can customize to be installed with the proper VPN configuration.

 

Check KB https://community.fortinet.com/t5/FortiClient/Technical-Tip-How-to-change-FortiClient-download-and-m... for details.

 

To have the users connecting to both IPSs, you can do it by DNS. Basically you need to advertise that the fqdn of your vpn gateway can be resolved to either one of your ISP addresses.

 

 

Also, 

Eudes Lima
muhammadsaad
Contributor

Anyone can help?

ebrlima

You can also use the EMS Invitations to share the installer and invite the users to join EMS:

 

https://docs.fortinet.com/document/forticlient/7.4.0/onboarding-for-ztna-deployment-guide/688483/inv...

Eudes Lima
muhammadsaad
Contributor

Allright, The Forticlient is not able to connect with the EMS through EMS server IP. When we asked for the IP, its requesting for the invitation code, whereas we want to only connect this via EMS server IP.

What will be the workout of this?

btan
Staff & Editor
Staff & Editor

Hi muhammadsaad,

 

The first thing to effectively use EMS is to publish your EMS to Internet (so that the telemetry can be reached from Internet (user working from home, not in office network). I have attached a quick sample guide pdf file. At the very least, allow port 8013 and 10443 from Internet to reach your EMS server.

Next, if right now there is no machine that can join to your EMS using IP (even using an private/internal IP), please check below:
-> Go to EMS -> System Settings, ensure that [Enforce User Verification] is unticked and [Enforce invitation-only registration for] is set to NONE.
enforce-none.png

Regards,
Bon
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors