Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
KevinYYC
New Contributor II

How do I associate an Endpoint Policy with a group of users?

I am using forticlient.forticloud.com/ems Version 7.4.3 build1926. I have deployed FortiClient 7.4.3.1790 to my endpoints.

 

I haven't found a way to access my on site DC.

2 Solutions
sharmar
Staff
Staff

Hello @KevinYYC 

 

You can sync your local AD with the EMS, so that you can apply the dynamic policy from the EMS, based on security group, OU or username etc. In the  EMS cloud case, sync the domain through AD connector would be the best approach. 

Please read this for more details: https://docs.fortinet.com/document/forticlient/7.4.3/ems-administration-guide/787816/ad-connector

 

Thanks

View solution in original post

sharmar
Staff
Staff

Hello @KevinYYC 

 

Then you can sync the local AD with EMS, using AD connector as proxy to your domain

 

Thanks

View solution in original post

10 REPLIES 10
jiahoong112
Staff
Staff

You will need to create an sslvpn or dialup ipsec profile on your FortiGate and then configure the vpn information in your FortiClient EMS Endpoint Profiles: https://docs.fortinet.com/document/fortigate/7.6.0/administration-guide/559546/ssl-vpn-full-tunnel-f...
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-configure-IPsec-dialup-VPN-using-ik...

 

https://docs.fortinet.com/document/forticlient/7.4.3/administration-guide/247767/configuring-and-app... 

**If you come across a resolution, kindly show your appreciation by liking and accepting it, ensuring its accessibility for others**
KevinYYC

After rereading my OP I can see there may be different ways to interpret my question.

 

My DC and endpoints are both on the LAN. The endpoints have access to the DC.

 

FortiClient EMS Cloud needs access to my DC. This is what I am trying to accomplish.

sharmar
Staff
Staff

Hello @KevinYYC 

 

You can sync your local AD with the EMS, so that you can apply the dynamic policy from the EMS, based on security group, OU or username etc. In the  EMS cloud case, sync the domain through AD connector would be the best approach. 

Please read this for more details: https://docs.fortinet.com/document/forticlient/7.4.3/ems-administration-guide/787816/ad-connector

 

Thanks

KevinYYC
New Contributor II

I am using FortiClient EMS Cloud.

sharmar
Staff
Staff

Hello @KevinYYC 

 

Then you can sync the local AD with EMS, using AD connector as proxy to your domain

 

Thanks

KevinYYC
New Contributor II

Hello @sharmar 

 

Thank you for your response.

 

This is a new deployment for a small business. There are only about 40 endpoints.

 

I went with the FortiClient EMS Cloud solution so I could avoid cost and maintenance of additional VMs. The AD connector was not part of deployment plan.

 

Initially I was given to believe that FortiClient EMS Cloud could be configured to access a local AD then was told that that capability had been removed.

 

Given the few endpoints and even fewer users it will be difficult to justify the deployment of an AD connector.

Given that, at this time, I only need three users in a group, is there any other way (manual?) to do this?

funkylicious

you could try and do a port forward for LDAP on the FGT onprem for AD, but this would expose the AD to Internet traffic unless you know the source IP of EMS Cloud instance.

haven't got the chance to work with the cloud version of it, but if it allows you to define a IP/port it should do it.

"jack of all trades, master of none"
"jack of all trades, master of none"
KevinYYC

@funkylicious 
Thank you for that suggestion but from what I can see In EMS Cloud, this option is not available. There's no UI or API to define LDAP server details like IP and port.

koletmo8
New Contributor

You can't associate an NSG directly with the Private Endpoint NIC. The best way to achieve what you want is to apply the NSG at the subnet level and then have the rule you need in the subnet level NSG referencing the specific IP for your Private Endpoint.

https://xender.vip/
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors