Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
CanerAltinel
New Contributor

Fortigate SSL VPN AV adn Custom Host Check Simultaniously?

Hi,

 

I want to check Antivirus and Registry Key for SSL VPN clients. But as I investigated, Fortigate doesn't allow host-check custom and host-check AV at the same time. I can check check AV and Registry seperately but I want to control both of them.

 

It may work the Antivirus instanceGuid and registry check, but when AV endpoint upgraded, the GUID will change and clients won't able to connect to VPN.

 

I can check if the AV endpoint .exe running, but this won't check for AV upgrades and it will just for one endpoint brand.

 

Is there any configuration for checking the registry key and AV at the same time?

4 REPLIES 4
gfleming
Staff
Staff

You could use Zero Trust Tags. While it won't prevent users from connecting to the VPN you can use tags in dynamic FW policies to prevent them from accessing any resources based on the tagging rules.

Cheers,
Graham
CanerAltinel

We are not using EMS. Trying to configure with Forticlient. Clients have 7.0.7 version

gfleming

Can you create multiple entries in the custom host check config?

 

 config check-item-list

 https://docs.fortinet.com/document/fortigate/7.2.3/administration-guide/32970/configuring-os-and-hos...

Cheers,
Graham
CanerAltinel

In config check-item-list, I can't use default AV check of the Fortigate. Yes I can config "ONE" antivirus GUID but that doesn't solve my problem. I want to use both default AV check which can be activated on GUI and my custom host check config. 

As you see below, I can  config "Host-check-policy" only custom or AV. 

All I want is activate both of them

 

config vpn ssl web portal
edit "tunnel-access"
set host-check custom
set host-check-policy "domain-check"

Labels
Top Kudoed Authors