Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
NTsun
New Contributor

Questions About EMS and Its Licensing

I have some questions regarding EMS. I want my Remote Access IPsec VPN users to have auto-connect and always-on capabilities.

  1. Are there any functional differences between EMS On-Premise and EMS Cloud licenses? Are there any limitations with one that do not exist on the other?
  2. Does the EMS On-Premise license come with its own installation package? Is it possible to deploy the EMS On-Premise installer on a cloud platform of my choice (e.g., Azure) without any issues?
  3. Aside from the Endpoint license packages, I understand there are also User-Based licenses.
  • How do they differ from Endpoint licenses?
  • When using a User-Based license, how does EMS Know that the user is using license, how does it identify the user, Is it tied to the AD username?


    5. Can a User-Based license for a single user be used on multiple devices? Let’s say I have an office with 4 laptops, all using the same AD user to connect via VPN, and all are connected simultaneously. Would a single User-Based license cover this scenario?

    6. Do User-Based licenses follow the same package structure as Endpoint licenses? For example, Endpoint licenses have separate packages for On-Premise and Cloud EMS — is it the same with User-Based licenses?

    7. Does the EMS server need to be publicly accessible at all times? When a user connects to FortiGate via VPN, do they first connect to EMS to retrieve their license before the VPN session begins?

    8. Does the device need to contact EMS for every VPN session, or is the license cached locally for some time? If cached, how long is the license valid without needing to reconnect to EMS?

    9. Can I make this type of thing work for Android phones(Specifically WMS Phones), I need this devices to have Auto connect and always on as well, with user-based or endpoint based licensing will I achieve this?
3 REPLIES 3
funkylicious
SuperUser
SuperUser

hi,

saw your posts on reddit also :) i will try to answer the points that i either know/read or found info about.

1. one diff that I saw/heard of that in order to add a Remote Auth source like LDAP/AD, if you have the Cloud version you would need an AD connector installed, the rest of the functions it think are the same

2. EMS on-prem license can be installed in theory if you have a Ubuntu 22.04/24.04 and the package is avail to download from the support portal, https://docs.fortinet.com/document/forticlient/7.4.3/ems-administration-guide/358374/system-requirem... 

3. https://docs.fortinet.com/document/forticlient/7.4.0/licensing-guide/305570/windows-macos-and-linux-... 

7. i think it's best that EMS should be accesible from Internet on tcp/8013 for telemetry at all times. this ensures that communication between endpoint and EMS is up2date for different things like policies, profiles, tags etc

8. you can configure in EMS for how long a device doesnt communicate with EMS for the license to be revoked

 

you should reach out to a local sales rep and get some official answers tho

"jack of all trades, master of none"
"jack of all trades, master of none"
NTsun

1. Can't I just Connect Cloud Version Directly to my On-prem AD?
7. What if I only Need Auto-connect and Always Up, does User still need connection to EMS server, Or Just Forigate Having Connection To EMS is enough?

funkylicious

1. not directly, you would need to install a application in order to connect/interogate your AD - https://docs.fortinet.com/document/forticlient/7.4.3/ems-administration-guide/787816 

7. auto-connect and always-on are VPN features and dont require a permanent connection to EMS as far as i know, but to they need to communicate initially in order to get the initial settings from it

"jack of all trades, master of none"
"jack of all trades, master of none"
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors