Hi,
We would like to make our telemetry connection safer by allowing only the clients that have the EMS certificate on their computers to make a telemetry connection. So we would like to enable "Use SSL certificate for Endpoint Control", but we have concern that it may cause all telemetry connection gets dropped.
We'd like to enable this option, and send a different profile, that has invalid certificate action drop action, to test computers. But again, we concern that enabling "Use SSL certificate for Endpoint Control" may cause all telemetry connection to drop. Has anyone experience this before? Can we enable certificate check for just test computers first?
Thanks and best regards
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Since this is a global change it will affect every client connection. I don't think there is a way to use it only for a group of computers. Some more details are shown here.
If the computers are part of a domain and if the certificate of the EMS is generated by the private CA of the domain you will be safe to apply this change since the computers will already have the CA on their trust store.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1641 | |
1069 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.