Change log 5 Introduction 6 Licensing 6 Special notices 7 Enabling full disk access 7 Activating system extensions 8 VPN 8 Web Filter and Application Firewall 8 Proxy mode extension 9 Enabling notifications 9 DHCP over IPsec VPN not supported 10 Running multiple FortiClient instances 10 FortiGuard Web Filtering Category v10 Update 10 Installation information 11 Firmware images and tools 11 Upgrading from previous FortiClient versions 11 Downgrading to previous versions 11 Uninstalling FortiClient 12 Firmware image checksums 12 Product integration and support 13 Language support 14 Resolved issues 15 Application Firewall 15 GUI 15 Remote Access 15 Logs 16 Web Filter and plugin 16 Endpoint control 16 FSSOMA 17 Malware Protection and Sandbox 17 ZTNA connection rules 17 Other 17 Known issues 18 Application Firewall 18 Avatar and social login information 18 Configuration 19 Deployment and installers 19 Endpoint control 19端点管理19端点政策和配置文件20端点安全20
Introduction 4 Features 4 Downloading FortiClient (Android) 7.2 5 Chromebook support 5 Product integration and support 7 Getting started 8 Launching FortiClient (Android) for the first time 8 Launching FortiClient (Android) from the notification bar 9 Quitting FortiClient (Android) from the app menu 9 Force stopping FortiClient (Android) from the Apps page 9 Web security 11 Web security status 12 Web security settings 12 VPN 14 SSL VPN 14创建SSL VPN连接14连接到VPN 19编辑SSL VPN设置或删除SSL VPN配置21启用/禁用自动启动22启动DTLS 22 IPSEC VPN 22 IPSEC VPN 23创建IPSEC VPN连接24连接到IPSEC VPN IPSEC VPN 2 28 EDEN 28 EDIND 2 28 EDIND 2 28 EDIND ODIND AT AT 2 28 EDIND OR EDITION ODITION ODITION ODITION ODITER ODITIND ODITION ODITION ODITIND ODITIND ODITIND ODITIND ODITIND ODITIND ODITIND ODITION ODITIS启用/禁用AutoStart 30推动VPN身份验证证书31 VPN证书路径31使用MDM推动VPN身份验证证书32独立VPN客户端33端点控制34 FortIcLient EMS 34配置Forticlient EMS EMS EMS EMS端口配置文件34 EMS连接机制36配置34 EMS INDER 36 EMS INDER 36配置36 EMPERTION 36权限39更改日志41
Introduction 9 FortiClient EMS components 9 Documentation 11 Getting started 12 Getting started with managing Windows, macOS, and Linux endpoints 12 Deploying FortiClient software to endpoints 12 Pushing configuration information to FortiClient 13 Relationship between FortiClient EMS, FortiGate, and FortiClient 14 Getting started with managing Chromebooks 18 Configuring FortiClient EMS for Chromebooks 18 Configuring the Google Admin console 18 Deploying a profile to Chromebooks 18 How FortiClient EMS and FortiClient work with Chromebooks 19 Installation preparation 20 System requirements 20 License types 21 FortiClient EMS 21 Component applications 24 Required services and ports 24 Management capacity 27 Hardware configuration when EMS and SQL Server run on same machine with no FortiGate connected 29 Hardware configuration when EMS and SQL Server run on different machines with no FortiGate connected 29 Hardware configuration when FortiGates are connected to EMS 30 FortiClient Telemetry security features 32 Server readiness checklist for installation 32 Upgrading from an earlier FortiClient EMS version 32 Upgrading EMS and FortiClient 33 Upgrading EMS from an earlier version 33 Install preparation for managing Chromebooks 34 Google Workspace account 34 SSL certificates 34 Installation and licensing 35 Downloading the installation file 35 Installing FortiClient EMS 35 Installing FortiClient EMS to specify SQL Server Enterprise or Standard instance 37 Installing FortiClient EMS using the CLI 40 Allowing remote access to FortiClient EMS and using custom port numbers 42 Customizing the SQL Server Express install directory 43 Starting FortiClient EMS and logging in 43 Configuring EMS after installation 44 Licensing FortiClient EMS 45
简介10 fortiClient EMS组件10文档12 BPS 13入门15开始管理Windows,Macos和Linux端点15最初将Forticlient软件部署到端点15将配置信息推向Forticlient 16 Forticlient 16的关系16 forticlient 16的关系16 forticlient的关系将个人资料部署到Chromebooks 21 21如何与Chromebook一起使用Chromebook 22安装准备23系统要求23系统要求23许可类型24 ForticLient EMS 24组件应用程序27所需的服务27所需的服务27遥测数据使用需求30管理能力30管理能力32在EMS和SQL No no no no no no no no fortere fortigate fortigate 33硬件33硬件33硬件时进行33硬件33硬件33的硬件。 FortiGate connected 34 Hardware configuration when there are FortiGates connected to the EMS 35 FortiClient Telemetry security features 36 Server readiness checklist for installation 36 Upgrading EMS 37 Upgrading from an earlier FortiClient EMS version 37 Auto upgrading EMS to latest patch release 39 Install preparation for managing Chromebooks 40 Google Workspace account 40 SSL certificates 41 Installation and licensing 42 Downloading the installation file 42 Installing FortiClient EMS 42 Installing FortiClient EMS to specify SQL Server Enterprise or Standard instance 44 Installing FortiClient EMS using the CLI 48 Allowing remote access to FortiClient EMS and using custom port numbers 50 Customizing the SQL Server Express install directory 50 Starting FortiClient EMS and logging in 51
Introduction 9 FortiClient EMS components 9 Documentation 11 Getting started 12 Getting started with managing Windows, macOS, and Linux endpoints 12 Initially deploying FortiClient software to endpoints 12 Pushing configuration information to FortiClient 13 Relationship between FortiClient EMS, FortiGate, and FortiClient 13 Getting started with managing Chromebooks 18 Configuring FortiClient EMS for Chromebooks 18 Configuring the Google Admin console 18 Deploying a profile to Chromebooks 18 How FortiClient EMS and FortiClient work with Chromebooks 19 Installation preparation 20 System requirements 20 License types 20 FortiClient EMS 21 Component applications 24 Required services and ports 24 Management capacity 27 Hardware configuration when EMS and SQL Server run on same machine with no FortiGate connected 28 Hardware configuration when EMS and SQL Server run on different machines with no FortiGate connected 29 Hardware configuration when there are FortiGates connected to the EMS 29 FortiClient Telemetry security features 30 Server readiness checklist for installation 31 Upgrading from an earlier FortiClient EMS version 31 Converting legacy Fabric Agent licenses 31 Upgrading EMS and FortiClient 32 Upgrading EMS from an earlier version 33 Install preparation for managing Chromebooks 33 Google Workspace account 33 SSL certificates 33 Installation and licensing 35 Downloading the安装文件35安装Forticlient EMS 35安装ForticLient EMS指定SQL Server Enterprise或Standard实例37使用CLI 39安装ForticLient EMS,允许远程访问ForticLient EMS访问ForticLient EMS并使用自定义端口编号42使用SQL Server SELPERS ENSTARK EXPERS 42启动Forticlient EMS和Divation 42 Insport forticlient EMS和div Ims in 43 in 33
Introduction 9 FortiClient EMS components 9 Documentation 11 Getting started 12 Getting started with managing Windows, macOS, and Linux endpoints 12 Deploying FortiClient software to endpoints 12 Pushing configuration information to FortiClient 13 Relationship between FortiClient EMS, FortiGate, and FortiClient 14 Getting started with managing Chromebooks 18 Configuring FortiClient EMS for Chromebooks 18 Configuring the Google Admin console 18 Deploying a profile to Chromebooks 19 How FortiClient EMS and FortiClient work with Chromebooks 19 Installation preparation 20 System requirements 20 License types 20 FortiClient EMS 21 Component applications 24 Required services and ports 24 Management capacity 27 Hardware configuration when EMS and SQL Server run on same machine with no FortiGate connected: 28 Hardware configuration when EMS and SQL Server run on different machines with no FortiGate connected 29 Hardware configuration when FortiGates are连接到EMS 29 FOTICLIENT遥测安全功能31服务器准备清单31从早期的Forticlient EMS版本升级32升级EMS和FortIclient 32升级EMS从较早版本的33安装准备工作中升级EMS,用于管理Chromebook 33 Google Workspace Altination 33 SSSL Installation 33 SSL Installing 33 SSL和BERTITICT 33 SSL INTERTITINC EMS 34 Installing FortiClient EMS to specify SQL Server Enterprise or Standard instance 36 Installing FortiClient EMS using the CLI 38 Allowing remote access to FortiClient EMS and using custom port numbers 41 Customizing the SQL Server Express install directory 41 Starting FortiClient EMS and logging in 42 Configuring EMS after installation 43 Licensing FortiClient EMS 44
如果您将EMS部署在EMS无法访问Internet的气动网络或隔离网络中,则可以配置EMS以接收Fortimanager的更新以部署到ForticLient。在离线模式下,Fortimanager允许从Fortimanager出口和导入Fortiguard软件包,以作为Fortiguard Distribution服务器提供。您可以将Fortiguard软件包从在线Fortimanager中导出到离线Fortimanager,该fortimanager为EMS提供签名和引擎更新。EMS接收防病毒,Web过滤器,应用防火墙,漏洞扫描以及Sandbox签名和发动机更新从Fortimanager中进行更新,并在气动或孤立的网络中部署更新到ForticLient。
本文档提供了管理员如何要求用户提供凭据以安全地连接并注册到EMS的示例,这是启用零信任网络访问的一部分。不需要用户身份验证或邀请代码,没有什么可以阻止未经授权的用户注册到您的EMS,接收您的配置并可能损害您的安全性。本部署指南展示了使用邀请码和用户身份验证的最佳实践,可以安全地登机到EMS。
pareloadCertificateFileName EMS_ZTNA_CA.CER pareloadContent <! EMS ZTNA CA证书 有效LoadIdentifier com.apple.security.security.root.1255e-c9f1-c9f1-4fbf-9967-4000ddf1df1df1df1df1df1dfc5 payloaduuid 1255DA5E-C9F1-4FBF-9967-4000DDF1DFC5 payloadversion 1 1
如果EMS管理的Chromebook数量超过了可用的Chromebook许可证的数量,请使用任何可用的零信任网络访问(ZTNA)许可证获得额外的Chromebook许可。例如,考虑您的EMS实例有50个Chromebook许可证,但是80个Chromebook连接到EMS实例。EMS使用Chromebook许可证50张Chromebooks,并使用30个ZTNA许可证(如果有)获得剩余的30个Chromebook(如果有)。如果没有Chromebook许可,则仅使用ZTNA许可证获得Chromebook的许可。有关ZTNA许可证的信息,请参见第2页的Windows,MacOS和Linux许可证。