Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
fsckawk
New Contributor

Forticlient and computers with several system accounts.

Hello. I've found two problems with Forticlient in computers with several accounts.

My setup: macOS Big Sur 11.7.7 and Forticlient 7.0.7.0245 free version.

1.- When a user is connected to the VPN server, if you switch accounts (instead of closing the active one), the second user can't nor use the VPN (ok) neither create his own new VPN connection.

I'm not sure about the "right" solution. Perhaps Forticlient could detect the switch of users and deactivate itself.

2.- User settings are shared among system accounts, so every user overwrittes the configuration of the previous user.
Forticlient stores VPN settings on a shared file with rw permissions for everyone.

/Library/Application Support/Fortinet/FortiClient/conf/vpn.plist

I think that vpn.plist should be stored in $HOME/Library/Application Support/Fortinet/FortiClient/conf/vpn.plist instead of in a system wide file.


I guess I could write a setuid root program to kill every other user's Forticlient proccess and replace vpn.plist, but is not a "clean" solution...

3 REPLIES 3
Jean-Philippe_P
Moderator
Moderator

Hello fcskawk, 

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible. 

 

Thanks, 

Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Moderator
Moderator

Hello,

 

We are still looking for an answer to your question.

 

We will come back to you ASAP.

 

 

Thanks,

Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Moderator
Moderator

Hello fsckawk,

 

 

There is a feature in ems advanced settings under the remote access profile to enable single-user mode, however, that requires a licensed FortiClient that is connected to EMS, this feature is not available in the Free FortiClient version.

 

You may raise a FortiGate ticket to report this issue and to investigate further, nevertheless there is a feature in EMS to enable single-user mode.

 

I hope it helped you, do not hesitate if you have more questions.

 

Regards,

Jean-Philippe - Fortinet Community Team
Labels
Top Kudoed Authors