- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How integrate AD with forticlient CLOUD EMS
How integrate AD with FortiClient CLOUD EMS
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Oksar,
The procedure should be the same as on-prem EMS:
https://docs.fortinet.com/document/forticlient/7.0.6/ems-administration-guide/123277/adding-endpoint...
Bon
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
emmm... So what? I need open port from the internet to my AD servers?
So how can i do this safely? bcs open port to AD servers is not very secure options.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You have to indeed open port to at least your EMS Cloud server public IP.
You can locate your EMS public IP in the about tab at the bottom left when you login to EMS Cloud.
Bon
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Still not very safe if someone spoof ip adress.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Did you ever get this implemented? I don't understand which IP to use on the EMS Cloud config to see the internal AD Server? I've found my public address for EMS Cloud to allowlist to the internal AD server - but how would EMS Cloud know how to route to the internal address of the AD Server?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Well, first you have to open ports for LDAP(s) on some your public IP, and instead of opening it to all (internet), you will use as source IP your Public IP of FortiClient EMS Cloud.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Opening Ports to LDAPs or much worse to Windows AD servers on Your firewall is insecure!
To end all that bad guessing. There is an ADConnector. See FortiDocs here: https://docs.fortinet.com/document/forticlient/7.2.2/ems-administration-guide/787816/ad-connector
Martin
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
That appears to be for On-prem EMS. Is there an option for cloud EMS?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @smalls ,
AD Connector can be setup for EMS Cloud as well. In fact the purpose for AD Connector is usually for EMS Cloud, but it is still very niche usage, since it increases management overhead (you will have to upgrade Connector version when EMS version is upgraded).
Bon
