Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rjcou1
New Contributor

Retrieving forticlient user's public IP address via EMS?

Hello,

 

In the EMS portal you can see the public IP of each registered forticlient user (on or off VPN), it's obviously collected data. Unfortunately the API only retrieves their local network IP address. Is there anyway to fetch the public IP address of a user that is not connected to VPN? Some useful scripting that could be done. I also noticed in FortiGate the endpoints API endpoint seems to have similar data, short of a public IP address.


Just curious if anyone knew if this was doable with the tools available via FortiClient EMS.

6 REPLIES 6
Anthony_E
Community Manager
Community Manager

Hello rjcou1,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Anthony-Fortinet Community Team.
Anthony_E
Community Manager
Community Manager

Hello rjcou1,

 

We are still looking for someone to help you.

We will come back to you ASAP.


Regards,

Anthony-Fortinet Community Team.
Anthony_E
Community Manager
Community Manager

Hello rjcou1,

 

I have found this document which can help you:

https://docs.fortinet.com/document/forticlient/7.2.3/administration-guide/708506/retrieving-user-det...

 

Tell us if it is not and we will continue to investigate.

 

Regards,

Anthony-Fortinet Community Team.
GaboBast1
New Contributor

Hello


The answer to the OP's original question would be useful to me too, but the link provided by Anthony is irrelevant in my opinion.
The nicest thing would be to collect the Public IP list of FortiClients to the integrated Fortigate via the Fabric Connector in a dynamic address group ( same Device IP and MAC addresses lists)
This could obviously be used in various source IP/MAC Based Access Control based rules

 

Junuzzz
New Contributor

link provided is irrelevant as GaboBast1 mentioned. This would be very helpful as we can use this in many control/firewall rules.

RJ1
New Contributor III

Fort iClient public IP, which is the end user's public IP, is not visible in Forti Analyzer traffic logs. Only the private IP is displayed. Is there a reason for this?

SJ
SJ
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors