Hello everyone,
We are managing around 500-600 FortiClient endpoints and need to upgrade clients quickly whenever vulnerabilities are announced.
Current setup:
From the infrastructure side, there is no clear technical explanation why EMS must remain closed, but we have to follow this decision.
Issues with ManageEngine upgrades:
Endpoints are EMS-connected and we perform in-place upgrades, yet problems persist.
Questions:
We would appreciate hearing how others are handling this in real-world environments.
Thank you.
Hi Firedoom
Regarding Q2, EMS is a security equipment that is intended to be published (at least Telemetry and ZTNA GW ports).
All what I can recommend when doing so is to keep it patched to avoid vulnerabilities, and you can also restrict access with GeoIP based rule (at firewall level) to limit the eventual attacks.
| User | Count |
|---|---|
| 2862 | |
| 1445 | |
| 829 | |
| 820 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.