Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Alex1
New Contributor II

Register the Forticlient endpoint to ForticlientEMS via the Internet.

Hi Team,

My Forticlient EMS is behind a Fortigate NAT , port 8013. Can I connect to EMS from my client on a public IP with a port? For example: 3.3.3.3:8013 Or do I have to use fqdn?

FortiClient,FortiGate, FortiClient, FortiAuthenticator, FortiDB

Снимок.PNG

RickSanchez
RickSanchez
1 Solution
gfleming
Staff
Staff

Disable 'Enforce User Verification' that should get rid of the invitation code requirement: https://docs.fortinet.com/document/forticlient/7.0.7/ems-administration-guide/319002/configuring-ems...

 

Then see how it behaves.

Cheers,
Graham

View solution in original post

4 REPLIES 4
gfleming
Staff
Staff

You can use FQDN or IP address. Both work.

Cheers,
Graham
Alex1
New Contributor II

Hi, 

Weird. I'm trying to connect to EMS using a public IP. But the client asks for the invite code. But since EMS is behind Fortigate's NAT, the invite code uses a private ip. In this situation, Forticlient definitely cannot connect to EMS over the Internet.

 

Alex1_0-1671175000298.pngAlex1_1-1671175062375.png

I see an incoming connection, but for some reason the server resets it

Alex1_0-1671176512018.png

Reinstalled the client to an earlier version, and now I get this error

Alex1_0-1671183776428.png

I disabled the Use SSL certificate for Endpoint Control. But for some reason I get this error

Alex1_0-1671188762601.png

 

 

RickSanchez
RickSanchez
gfleming
Staff
Staff

Disable 'Enforce User Verification' that should get rid of the invitation code requirement: https://docs.fortinet.com/document/forticlient/7.0.7/ems-administration-guide/319002/configuring-ems...

 

Then see how it behaves.

Cheers,
Graham
Alex1
New Contributor II

Great. That helped!

RickSanchez
RickSanchez
Labels
Top Kudoed Authors