I am using forticlient.forticloud.com/ems Version 7.4.3 build1926. I have deployed FortiClient 7.4.3.1790 to my endpoints.
I haven't found a way to access my on site DC.
Solved! Go to Solution.
Hello @KevinYYC
You can sync your local AD with the EMS, so that you can apply the dynamic policy from the EMS, based on security group, OU or username etc. In the EMS cloud case, sync the domain through AD connector would be the best approach.
Please read this for more details: https://docs.fortinet.com/document/forticlient/7.4.3/ems-administration-guide/787816/ad-connector
Thanks
Hello @KevinYYC
Then you can sync the local AD with EMS, using AD connector as proxy to your domain
Thanks
You will need to create an sslvpn or dialup ipsec profile on your FortiGate and then configure the vpn information in your FortiClient EMS Endpoint Profiles: https://docs.fortinet.com/document/fortigate/7.6.0/administration-guide/559546/ssl-vpn-full-tunnel-f...
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-configure-IPsec-dialup-VPN-using-ik...
After rereading my OP I can see there may be different ways to interpret my question.
My DC and endpoints are both on the LAN. The endpoints have access to the DC.
FortiClient EMS Cloud needs access to my DC. This is what I am trying to accomplish.
Hello @KevinYYC
You can sync your local AD with the EMS, so that you can apply the dynamic policy from the EMS, based on security group, OU or username etc. In the EMS cloud case, sync the domain through AD connector would be the best approach.
Please read this for more details: https://docs.fortinet.com/document/forticlient/7.4.3/ems-administration-guide/787816/ad-connector
Thanks
I am using FortiClient EMS Cloud.
Hello @KevinYYC
Then you can sync the local AD with EMS, using AD connector as proxy to your domain
Thanks
Hello @sharmar
Thank you for your response.
This is a new deployment for a small business. There are only about 40 endpoints.
I went with the FortiClient EMS Cloud solution so I could avoid cost and maintenance of additional VMs. The AD connector was not part of deployment plan.
Initially I was given to believe that FortiClient EMS Cloud could be configured to access a local AD then was told that that capability had been removed.
Given the few endpoints and even fewer users it will be difficult to justify the deployment of an AD connector.
Given that, at this time, I only need three users in a group, is there any other way (manual?) to do this?
Created on 08-02-2025 10:24 AM Edited on 08-02-2025 10:26 AM
you could try and do a port forward for LDAP on the FGT onprem for AD, but this would expose the AD to Internet traffic unless you know the source IP of EMS Cloud instance.
haven't got the chance to work with the cloud version of it, but if it allows you to define a IP/port it should do it.
@funkylicious
Thank you for that suggestion but from what I can see In EMS Cloud, this option is not available. There's no UI or API to define LDAP server details like IP and port.
You can't associate an NSG directly with the Private Endpoint NIC. The best way to achieve what you want is to apply the NSG at the subnet level and then have the rule you need in the subnet level NSG referencing the specific IP for your Private Endpoint.
User | Count |
---|---|
2592 | |
1380 | |
800 | |
659 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.