Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
AtiT
Valued Contributor

FortiClient deployment via GPO with EMS IP address

Hello,

I have a task from customer to create an installation package for GPO deployment where the FortiClient will automatically connect to EMS after the installation.

I have a FortiClient installed and connected to EMS and it is synced with the EMS. I downloaded the config file from FortiClient but I cannot see the IP address of the EMS server in it.

When I create a package with configuration tool and install the MSI with MST the client shows a blank address field for EMS waiting for enterign the IP address and click connect.

 

Is there any way to create MSI, MST file for GPO deployment with EMS configured?

AtiT

AtiT
4 REPLIES 4
vinceneil666
Contributor

Hi,

I have just been trough the same. What you need to look into, is that when you build the msi file - you can add both the config file and the gateway list initially.  (the EMS stuff is encrypted, se link below) .. Make sure you use a key!!!

 

Look at this:

http://help.fortinet.com/fclient/olh/5-4-1/Content/FortiClient-5.4-Admin/1500_Custom%20Installation/...

 

In the EMS you can add both a profile and a gateway list to the OU where your machines are. Go in and create both, and you will get the idea when you create the gateway list.. put in your ems there. 

 

Tip! .. do make an OU for testing :) Youll need it :)

 

I had a guy doing the xml work to seperate the ems stuff from the config file. Then created both profile and gateway list on ems.. Works fine - it will usually take 5-10 seconds after install until it connects first time.

 

vinceneil666

Note! .. You can also create both profile config and gateway list in ems.. Then choose to export them both, and then use the files when building the MSI ... A bit easier that pulling out the EMS stuff from the config of the client itself.

 

SteveG

This is how we do it and it works really well. FC auto registers using the Connection Key specified in the Gateway list.

AtiT
Valued Contributor

It worked for me.

I downloaded the ednpoint profile and the gateway list from the EMS and built the MSI package.

 

Thank you very much!

AtiT

AtiT
Labels
Top Kudoed Authors