Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
miciti
New Contributor III

FortiClient EMS: prevent unknown devices from connecting?

Hello everyone,

I am new to FortiClient EMS and currently in a roll-out state.

 

How do I prevent unwanted computers from connecting to the EMS? (EMS on-prem, running in a DMZ and public available to the internet)

 

In theory someone can install FortiClient and connect to our EMS.

I do install FortiClient for our users because they do not have admin privileges - so I did not enable user verification.

 

Is there any other way to prevent unwanted devices from connecting to EMS?

3 REPLIES 3
spoojary
Staff
Staff

Enable 'Enforce User Verification' in the EMS settings. This will require end users to provide credentials to connect to EMS, adding an extra layer of security. Enable 'Enforce Invitation-Only Registration' to ensure that new devices can only join the EMS via an invitation code, rather than directly connecting using the EMS IP or FQDN.
https://docs.fortinet.com/document/forticlient/7.0.7/ems-administration-guide/002758/invitations

https://docs.fortinet.com/document/forticlient/7.0.7/ems-administration-guide/319002/configuring-ems...

Siddhanth Poojary
miciti
New Contributor III

I see, thanks for your reply.

 

Since my end users does not have admin privileges on their company devices they are not able to install FortiClient on their own.
The IT department uses a temporary local account with admin privileges to do so on company LAN... I want to connect "devices" to EMS and not users, does the user verification has to be done for all users of one PC or is it enough to do it once during installation?

 

Hartza
New Contributor II

Hi,

Did you find any solutions for your questions?  I have the same issue. After installing the client via SCCM the installation prompts the login since invitation verification type is SAML. Problem is that  when another user (the real end user) logged in the computer the Fortliclient is not connected to EMS Cloud anymore and verification code is needed. Is there a way to challenge the login to new users as well or some another way to autoregister host to EMS after another users logins to computer.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors