- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Forticlient invitation code on public IP
Hello,
EMS is behind the firewall but the invitation code is based on the internal FQDN.
How can I solve this ? Manual entries are not allowed.
KR
Laurent
- Labels:
-
FortiClient
-
FortiClient EMS
Created on ‎12-25-2023 12:31 AM Edited on ‎12-25-2023 12:33 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello @lpi ,
You can configure your public IP address or fqdn on EMS settings. After that, this invitation will be sent with a configured fqdn or IP.
NSE 4-5-6-7 OT Sec - ENT FW
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you for sharing valuable insight.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
I am of course already using the FQDN but with the internal server resolution.
If I put the external FQDN, all internal traffic will be also routed back to this VIP address instead of the local internal address. Moreover port 443 is not allowed on that external VIP.
KR
Laurent
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You have to add an entry on the public DNS that resolves the FQDN of EMS to the public IP (VIP) you have configured in the firewall.
For the internal DNS you could configure the same FQDN to be resolved to the private IP address of the EMS.
Since the initiation will contain the domain only, it will work for both clients in public and private network.
If you have found a solution, please like and accept it to make it easily accessible for others.
