I have some questions regarding EMS. I want my Remote Access IPsec VPN users to have auto-connect and always-on capabilities.
hi,
saw your posts on reddit also :) i will try to answer the points that i either know/read or found info about.
1. one diff that I saw/heard of that in order to add a Remote Auth source like LDAP/AD, if you have the Cloud version you would need an AD connector installed, the rest of the functions it think are the same
2. EMS on-prem license can be installed in theory if you have a Ubuntu 22.04/24.04 and the package is avail to download from the support portal, https://docs.fortinet.com/document/forticlient/7.4.3/ems-administration-guide/358374/system-requirem...
7. i think it's best that EMS should be accesible from Internet on tcp/8013 for telemetry at all times. this ensures that communication between endpoint and EMS is up2date for different things like policies, profiles, tags etc
8. you can configure in EMS for how long a device doesnt communicate with EMS for the license to be revoked
you should reach out to a local sales rep and get some official answers tho
1. Can't I just Connect Cloud Version Directly to my On-prem AD?
7. What if I only Need Auto-connect and Always Up, does User still need connection to EMS server, Or Just Forigate Having Connection To EMS is enough?
Created on ‎08-08-2025 05:36 AM Edited on ‎08-08-2025 05:39 AM
1. not directly, you would need to install a application in order to connect/interogate your AD - https://docs.fortinet.com/document/forticlient/7.4.3/ems-administration-guide/787816
7. auto-connect and always-on are VPN features and dont require a permanent connection to EMS as far as i know, but to they need to communicate initially in order to get the initial settings from it
User | Count |
---|---|
2561 | |
1357 | |
796 | |
650 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.