Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
droehrig
New Contributor II

Forticlient EMS Endpoint Notified

After an auto deployment I have many endpoints that only say under Installer- Endpoint Notified but they never updated to the latest version. How do I fix this? It happens every time there is an update to the Forticlient and we do an auto deployment of the update. 

 

Thanks,

Donna

5 REPLIES 5
Mario_M
New Contributor II

Hi Donna,

 

any news about this topic?

 

TIA
Mario

IT_Satcom
New Contributor

Would like to hear about as well, the same problem here.

hirozawa
New Contributor II

※I am using translation software, so the sentences may be difficult to understand.

 

The cause of the problem may be an invalid certificate.

I changed "Invalid Certificate Action" to "Allow" in "System Setting Profile" of "Endpoint Profile". Then, when I configured the "Deployment" again, a notification was displayed to the user.

mgoswami
Staff
Staff

Hello,

 

What network ports are allowed between endpoints and EMS ? Please check the Firewall and ensure that following ports are open "TCP 135, 445, and 10443 ports between EMS Server".

 

Regards,

Manosh

hirozawa
New Contributor II

I didn't know how this feature actually worked.
Here are the results of my investigation:

 

1. EMS notifies FortiClient of the "System Settings >> EMS Settings >> EMS Settings" field, specifically the "FortiClient Download URL."
2. FortiClient accesses the notified URL to download the package.
3. The client installs the downloaded package.


I mistakenly thought the package was downloaded through telemetry (port 8013)!
The reality is that the download URL (port 10443) is notified, and the package is retrieved from there.

Even if a user doesn't utilize the download URL,
users who use the "Manage Deployment" feature should ensure that TCP/10443 is accessible for communication!

 

Furthermore, if the download URL displays a certificate warning,
it is recommended to set the "Invalid Certificate Action" to "Allow" in the system profile.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors