Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
FNT_Learner
New Contributor III

fortinet ZTNA licensing

Hello everyone!

Please help me if anyone has experience or worked with implementing Fortinet ZTNA. I want to implement ZTNA in my network. but I don't know which subscription is necessary for that. Do I need valid subscription on my FortiGate? which subscription should I purchase for Endpoints or Forti Client EMS? 

Any of Fortinet Support Can help me? I need a Comprehensive guide, please.

Thanks. 

1 Solution
ozkanaltas
Valued Contributor III

My advice is; to first install FortiClient EMS with a trial license on your lab or prod environment. Try some scenarios related to your request. After that purchase a prod license.

 

In the installation stage, you can follow this document. Especially, be careful installing Windows server. Language, time, and currency format settings it should be "English (United States)". Based on my past experience, do not install anything on this server. When different programs are installed, EMS may sometimes cause errors during installation.

 

https://docs.fortinet.com/document/forticlient/7.2.3/ems-administration-guide/358374/system-requirem...

 

If my answer provided a solution for you. Please do not forget to mark it as a solution so that others can benefit from it.

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW

View solution in original post

If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
8 REPLIES 8
ozkanaltas
Valued Contributor III

Hello @FNT_Learner ,

 

You don't need an additional Fortigate license for ZTNA. But You should buy a FortiClientEMS VPN/ZTNA license for endpoints. If you want to use additional features on FortiClient. You can review this table and you can select the license best for you. 

 

If you want to try ZTNA. You can install FortiClientEMS with your support account. FortiClientEMS provides always a free trial for 3 clients. 

 

image.png

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
FNT_Learner

Hi ozkanaltas thank you for your quick response. so the only license that is needed is FortiClientEMS VPN/ZTNA license and this just should be applied on EMS, not clients. is it correct? and what about the clients, do they need any license for enabling ZTNA functionality on them? As I know we need a license for endpoints and another license for EMS to manage them. is it right?

ozkanaltas
Valued Contributor III

Hi @FNT_Learner ,

 

Actually, you should buy a FortiClientEMS license up to your client count. If you look at the FortiClientEMS data sheet. You can see the client package up to your client count. Your client will get their licenses from FortiClientEMS.

 

FortiClientEMS is the only management console for FortiClient. Also, EMS shares your client's ZTNA tag and Client certificate with Fortigate. In this way, trust is established between Fortigate and the Client.

 

Also, you have two options for the FortiClientEMS deployment method. Cloud and Self-Hosted. If you select a Cloud-based license, this license type is user-based. You can install 3 machines (computer, cell phone, tablet) with the same username. But if you choose self-hosted, this license device-based. You should buy up to your device count.

 

These licenses are stackable. For example, if you need 100 client licenses. You can buy 25 packs x 4.

 

https://www.fortinet.com/content/dam/fortinet/assets/data-sheets/forticlient.pdf

 

image.png

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
FNT_Learner

Thank you. I plan to deploy EMS server on-prem. is there any additional tips that you want tell me?

ozkanaltas
Valued Contributor III

My advice is; to first install FortiClient EMS with a trial license on your lab or prod environment. Try some scenarios related to your request. After that purchase a prod license.

 

In the installation stage, you can follow this document. Especially, be careful installing Windows server. Language, time, and currency format settings it should be "English (United States)". Based on my past experience, do not install anything on this server. When different programs are installed, EMS may sometimes cause errors during installation.

 

https://docs.fortinet.com/document/forticlient/7.2.3/ems-administration-guide/358374/system-requirem...

 

If my answer provided a solution for you. Please do not forget to mark it as a solution so that others can benefit from it.

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
FNT_Learner

Thank you ozkanaltas.

FNT_Learner

Hello ozkanaltas,

would you please tell me about licensing for EPP/APT? if I want to have subscription for this product, what licenses should I purchase? and which device is responsible for distributing updates to client? FortiGate or EMS? if FortiGate is responsible for that, does it need license too?

ozkanaltas
Valued Contributor III

Hello @FNT_Learner ,

 

EMS is responsible for the updates. 

 

If you want to use the ztna feature, you can buy only the ztna license. If you want additional features, for example, antivirus, USB device control, ransomware protection.  You should buy EPP/APT license. You can see the difference between these licenses in the screenshot. 

 

image.png

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors