随着Fortiedr和Forticlient EMS的集成,当分配给Fortiedr保护的端点的安全策略触发“零信任设备标记”自动事件响应(AIR)剧本时,Fortiedr会自动将API更新发送到ForticLient EMS实例。此更新将分类或织物标签应用于目标端点,只要FortIclient EMS具有匹配的ForticLient管理的端点,并带有匹配的设备名称。forticlient EMS上存在的分类或织物标签已直接分配给受影响的端点。如果尚不存在分类标签,则Forticlient EMS会自动创建一个并将其分配给受影响的端点。
本文档提供了管理员如何要求用户提供凭据以安全地连接并注册到EMS的示例,这是启用零信任网络访问的一部分。不需要用户身份验证或邀请代码,没有什么可以阻止未经授权的用户注册到您的EMS,接收您的配置并可能损害您的安全性。本部署指南展示了使用邀请码和用户身份验证的最佳实践,可以安全地登机到EMS。
Introduction 7 FortiClient, FortiClient EMS, and FortiGate 7 Fortinet product support for FortiClient 7 FortiClient EMS 8 FortiManager 8 FortiGate 8 FortiAnalyzer 9 FortiSandbox 9 Feature comparison of FortiClient standalone and licensed versions 9 Endpoint communication security improvement 11 Recommended upgrade path 12 Getting started 17 Getting started with FortiClient 17 EMS and endpoint profiles 18 Telemetry connection options 18 EMS 22供应要求22授权23所需的服务和端口23固件图像和工具26 Microsoft Windows 26 Macos 27 Linux 27获取Forticlient安装文件28手动在计算机上安装Forticlient 29 Microsoft Windows 29 Macos 30 MacOs 30 linient fortict forticn 37磁盘图像38使用CLI 38安装forticlient forticlient部署39 Forticlient EMS 40使用Microsoft Ad服务器部署forticlient,使用Microsoft Ad服务器40卸载Forticlient 41升级Forticlient 41升级Forticlient 41验证EMS和EMS和Forticlient 41和Forticlient 41和Fortist and Fortient and Fortient and Fortistion 41
Change log 5 Introduction 6 Licensing 6 Special notices 7 Enabling full disk access 7 Activating system extensions 8 VPN 8 Web Filter and Application Firewall 8 Proxy mode extension 9 Enabling notifications 9 DHCP over IPsec VPN not supported 10 Running multiple FortiClient instances 10 FortiGuard Web Filtering Category v10 Update 10 Installation information 11 Firmware images and tools 11 Upgrading from previous FortiClient versions 11 Downgrading to previous versions 11 Uninstalling FortiClient 12 Firmware image checksums 12 Product integration and support 13 Language support 14 Resolved issues 15 Application Firewall 15 GUI 15 Remote Access 15 Logs 16 Web Filter and plugin 16 Endpoint control 16 FSSOMA 17 Malware Protection and Sandbox 17 ZTNA connection rules 17 Other 17 Known issues 18 Application Firewall 18 Avatar and social login information 18 Configuration 19 Deployment and installers 19 Endpoint control 19端点管理19端点政策和配置文件20端点安全20
Introduction 9 FortiClient EMS components 9 Documentation 11 Getting started 12 Getting started with managing Windows, macOS, and Linux endpoints 12 Deploying FortiClient software to endpoints 12 Pushing configuration information to FortiClient 13 Relationship between FortiClient EMS, FortiGate, and FortiClient 14 Getting started with managing Chromebooks 18 Configuring FortiClient EMS for Chromebooks 18 Configuring the Google Admin console 18 Deploying a profile to Chromebooks 18 How FortiClient EMS and FortiClient work with Chromebooks 19 Installation preparation 20 System requirements 20 License types 21 FortiClient EMS 21 Component applications 24 Required services and ports 24 Management capacity 27 Hardware configuration when EMS and SQL Server run on same machine with no FortiGate connected 29 Hardware configuration when EMS and SQL Server run on different machines with no FortiGate connected 29 Hardware configuration when FortiGates are connected to EMS 30 FortiClient Telemetry security features 32 Server readiness checklist for installation 32 Upgrading from an earlier FortiClient EMS version 32 Upgrading EMS and FortiClient 33 Upgrading EMS from an earlier version 33 Install preparation for managing Chromebooks 34 Google Workspace account 34 SSL certificates 34 Installation and licensing 35 Downloading the installation file 35 Installing FortiClient EMS 35 Installing FortiClient EMS to specify SQL Server Enterprise or Standard instance 37 Installing FortiClient EMS using the CLI 40 Allowing remote access to FortiClient EMS and using custom port numbers 42 Customizing the SQL Server Express install directory 43 Starting FortiClient EMS and logging in 43 Configuring EMS after installation 44 Licensing FortiClient EMS 45
Introduction 9 FortiClient EMS components 9 Documentation 11 Getting started 12 Getting started with managing Windows, macOS, and Linux endpoints 12 Deploying FortiClient software to endpoints 12 Pushing configuration information to FortiClient 13 Relationship between FortiClient EMS, FortiGate, and FortiClient 14 Getting started with managing Chromebooks 18 Configuring FortiClient EMS for Chromebooks 18 Configuring the Google Admin console 18 Deploying a profile to Chromebooks 19 How FortiClient EMS and FortiClient work with Chromebooks 19 Installation preparation 20 System requirements 20 License types 20 FortiClient EMS 21 Component applications 24 Required services and ports 24 Management capacity 27 Hardware configuration when EMS and SQL Server run on same machine with no FortiGate connected: 28 Hardware configuration when EMS and SQL Server run on different machines with no FortiGate connected 29 Hardware configuration when FortiGates are连接到EMS 29 FOTICLIENT遥测安全功能31服务器准备清单31从早期的Forticlient EMS版本升级32升级EMS和FortIclient 32升级EMS从较早版本的33安装准备工作中升级EMS,用于管理Chromebook 33 Google Workspace Altination 33 SSSL Installation 33 SSL Installing 33 SSL和BERTITICT 33 SSL INTERTITINC EMS 34 Installing FortiClient EMS to specify SQL Server Enterprise or Standard instance 36 Installing FortiClient EMS using the CLI 38 Allowing remote access to FortiClient EMS and using custom port numbers 41 Customizing the SQL Server Express install directory 41 Starting FortiClient EMS and logging in 42 Configuring EMS after installation 43 Licensing FortiClient EMS 44
