FortiClient EMS Course Notes
FortiClient EMS Course Notes
FortiClient EMS Course Notes
Forticlient (EMS)
ForiClient (FC)
FortiClient
EMS Course FortiGate(FG)
Notes
FortiAnalyzer(FAZ)
Installation Packages
Forticlient (EMS)
Forticlient (EMS)
Features
Benefits
Components
Vulenrability Management
EDR
Forticlient (EMS)
Features
FortiClient EMS shares device status information through
ZTNA telemetry
Benefits
Remote deployment of FC S/W to Windows PCs
Components
FC EMS
EMS Database
FortiClient
Webfilter Extension
ZTNA
Forticlient (EMS)
FC EMS
Manages FC on endpoints
EMS Database
Stores security profiles & events
FortiClient
Ensforces security & protection on endpoints
Webfilter Extension
Communicates with EMS to enforce web filtering on
Chromebooks
Rate IP address:
Filters URL & resolve IP address at same time and select required action
Exclusion List:
Has higher priority than site categories
Violations:
Forticlient (EMS)
Violations:
List of all violated Fortiguard categories when actions are
block/warn
ZTNA
ZT Telemetry / FC Telemetry
Telemetry Data
ZTNA Rule:
Forticlient (EMS)
ZT Telemetry / FC Telemetry
Shows connectivity b/w FC & EMS
FQDN
Invitation Codes
Forticlient (EMS)
No mix is allowed
Forticlient (EMS)
Telemetry Data
This data is sent to EMS
It consists of :
Forticlient (EMS)
It consists of :
H/W info (macOS)
Workload
Forticlient (EMS)
ZTNA Rule:
It is proxy policy which enforces access control
Vulenrability Management
An administrator is required to maintain a software vulnerability on the
endpoints, without showing the feature on the FortiClient dashboard. Click the
hide icon on the vulnerability scan tab
Managed by EMS
EDR
Prevents Post-Execution Suspicious activities
Users Administration
Admin User
Forticlient (EMS)
Admin User
Manages permissions, approvals, discovery and
deployment of FC
Roles of Administrators
Super admin
Standard admin
Endpoint admin
Restricted admin
Policy permissions
Settings permissions
Forticlient (EMS)
Users Settings
Inactivity timeout (default 30 min)
Fabric Devices
Shows authorized FGs in FSF
Devices Roles:
Forticlient (EMS)
Devices Roles:
Device identity & trust are integrated to ZTNA
Stand-alone Mode:
EMS provisions endpoints
EMS Settings:
Shared EMS Settings:
EMS Settings:
Endpoints Settings:
EMS Settings:
Howendpoints connect to EMS
Endpoints Settings:
Timeout values:
Signature DB updatate
If you choose info log type, you will get all types from
Forticlient (EMS)
Timeout values:
Keepalive =60s, offline=5 days, EMS
license=45 days, Delete=30 days,
Deauthrozed user inactivity=30 days
Forticlient (EMS)
If not valid:
Forticlient (EMS)
If not valid:
If action is warn, and user allows connection, FC will
connect to EMS and remember action.
EMS in Multi-Tenancy:
Benefits:
Features:
Site Admin:
Site-Level License:
Forticlient (EMS)
Benefits:
Granular access to multiple sites for mutiple admins with
separate endpoints data & config info for each site
Up to 500 sites
Features:
You must enable "Manage Multiple Customer Site" option
Dashboard display:
Dashboard display:
Global settings for all sites
Site Admin:
Site Admin is a new role for site-level
Site-Level License:
ZT license
Fail-over Options:
Forticlient (EMS)
Active-Passive mode:
Both primary & secondary servers same remote DB in
separate server
Fail-over Options:
DNS Round-Robin:
HA Load-Balancer:
Forticlient (EMS)
DNS Round-Robin:
Same Hostname to multiple EMS servers with different IPs
HA Load-Balancer:
Uses FG to route traffic to EMS
using VIP, real IPs/Ports, LB,
health check
Forticlient (EMS)
Patch VUL on FC
IP address
OS platform: Win/macOS...
ForiClient (FC)
ForiClient (FC)
FC Features:
FC General Info:
Components
Quarantine Automation
ForiClient (FC)
FC Features:
FortiClient provides features such as antivirus, web filtering,
firewall, vulnerability scan, and VPN.
Necessity
ForiClient (FC)
FC General Info:
Types of AV scanning
Types of AV scanning
Quick Scan
Full Scan
Custom Scan
ForiClient (FC)
Quick Scan
Runs the rootkit detection engine to detect & remove
rootkits
Full Scan
Runs the rootkit detection engine to detect & remove
rootkits
Default is monthly
ForiClient (FC)
Custom Scan
Runs the rootkit detection engine to detect & remove
rootkits
Malware Protection in FC
Includes AV protection, anti-malware, cloud-based malware protection,
anti-exploit and removable media access
Network Support
FC supports IPSec & SSL VPN
Or Advanced
ForiClient (FC)
Or Advanced
Redundant IPSec VPN
User name/Password
Components
Application Firewall
ForiClient (FC)
Application Firewall
Uses IPS protocol decoder to detect & analyze apps traffic
even on non-standard ports
Quarantine Automation
AS Fabric agent, FC can integrate w/ security fabric
automated responses to contain incidents
Quarantineing Benefits:
Quarantineing Benefits:
Containing threats & icnidents
Controlling outbreaks
ForiClient (FC)
MS GPO
MDM
MDM
Intune: All platforms
Installer package
ForiClient (FC)
Advanced Features
ForiClient (FC)
Basic Features
ZT Telemetry (enabled by default)
Vulnerability Scan
APT
ForiClient (FC)
Advanced Features
AV, Anti-exploit, anti-ransomeware,app
f/w, SSOMA, cloud-based malware
outbreak detection
ForiClient (FC)
Endpoints Profiles:
Assigned/default profiles can not be deleted
Eye-icon feature:
Default profile:
Eye-icon feature:
Used for inspecting user traffic without their knowledge
Default profile:
Created in EMS during installation
Adult Sites
FortiGate(
FortiPAM(PAM)
FG)
SAML SSO
FortiGate(FG)
Features
Provides network & security
Uses verification rules & endpoints info from EMS to dynamically adjust
security policies
Firewall policies
FortiGate(FG)
Firewall policies
Applies security profiles to protect traffic using ZTNA
Configurations on FG for remote users
ZTNA Policies:
FortiGate(FG)
ZTNA Policies:
Full ZTNA Policy: Firewall policy matches and redirects
client requests to the access proxy VIP
FortiPAM(PAM)
Features
FortiGate(FG)
Features
A privileged access management solution
SAML SSO
Use FG as IdP to login to EMS
Central Topic
Questions
FortiAnalyzer(FAZ)
Features
Logging
FortiAnalyzer(FAZ)
Features
Provides network & security
FortiManager (FM)
Features
FortiAnalyzer(FAZ)
Features
Controls management for managed FGs
FortiSandbox(FSB)
Features
FortiAnalyzer(FAZ)
Features
Analyzes new, old unknown, udetected viruses samples
real-time
Logging
AV, App F/W, VPN, Web filter, Updates, VUS scanning logs
Status:
Status:
Emergency: system is unstable
Warning
Information (default)
FortiAnalyzer(FAZ)
EMS
FAZ or FM
Log Viewer:
View or download EMS logs (.zip
format)
FortiAnalyzer(FAZ)
Forensic Analysis:
Requires Forensic Analysis license
Generated Statuses:
FortiAnalyzer(FAZ)
Generated Statuses:
Pending: request initiated and waiting to be assigned to
analyst
Cancelled:
Analyst needs more info about endpoint
Installation
EMS Licenses
Packages
SASE Licenses
Installation Packages
FC Installations
Stand-alone
Using AD GPO
FortiPAM/FC Stand-alone
Installation Packages
Stand-alone
Windows
MacOS
Linux
Installation Packages
Windows
/quite: install in quite mode + log
MacOS
Online tool to download s/w and install
Installation Packages
Using AD GPO
GPO is used to install/uninstall
FortiPAM/FC Stand-alone
Requires ZTNA tunnel access to PAM server or FortiPAM without EMS
EMS Licenses
Supports Win, macOS, Android, Linux and Chromebook
EPP License
ZTNA License
Installation Packages
EPP License
Full license with all features in FC:
ZTNA, AV, Anti-ransome, CBM,
Application F/W, SI, APT, Sandbox
Installation Packages
ZTNA License
Support fabric agent, telemetry, security
posture via ZTNA tags, remote access,
VUS, Webfilter, threat protection and USB
device control
Installation Packages
Chromebook License
For one user
Installation Packages
ClientdownloadPort is 10443
RemoteManagmentPort is 443
Installation Packages
Access EMS
https://localhost (locally)
https://FQDN-server-name (remotely)
Installation Packages
SASE Licenses
Protects on/off campus users when
connected to internet using the same FG
access policies. (Subscription Only)
FortiSASE ISA
FortiSASE ISA
Features
FortiSASE ISA
Features
Security-as-a-Service-Internet Security Access
Has 4 Editions
Forticlient Security Fabric(FSF)
Features
Endpoints visibility through telemetry
Has 4 Editions
ZTNA
EPP/ATP
Managed Service
Chromebook
Forticlient Security Fabric(FSF)
ZTNA
An access control method that uses client device identification and
authorization and ZTNA tags to provide role-based access to apps of
on/off fabric users
Device Verification
Verification Rules Criteria
Login Domain
Files present
Registry Keys
Forticlient Security Fabric(FSF)
ZTNA Destination
ZTNA destination create non-VPN secure encrypted
connection to applications
FG checks and
allow/deny access
If allowed by admin, ZTNA destination
can be configured on FC itself:
Forticlient Security Fabric(FSF)
EPP/ATP
All ZTNA licenses - AV,Anti-malware,Anti-exploit
Managed Service
Initial FC cloud provisioning with customer to setup cloud enviornment
Endpoint onboarding
Vulnerability monitoring
Forticlient Security Fabric(FSF)
Chromebook
Manages one Google Chromebook user