FortiClient
FortiClient proactively defends against advanced attacks. Its tight integration with the Security Fabric enables policy-based automation to contain threats and control outbreaks. FortiClient is compatible with Fabric-Ready partners to further strengthen enterprises’ security posture.
volkanavsar
Staff
Staff
Article Id 312740
Description This article describes how to to address issues related to the EMS side of the new FortiClient Installer creation and signature updates.
Scope

FortiClient EMS, FortiClient Windows, FortiClient Linux, FortiClient MacOS.

Solution

First, make sure to allow the following domains on the FortiGate side.

 

forticlient.fortinet.net, TCP port 80

myforticlient.fortinet.net, TCP port 80

fctupdate.fortinet.net, TCP port 443

 

See Required services and ports - FortiClient EMS administration guide.

SSL Inspection should be assigned 'no-inspection' to the above addresses.

 

2024-05-02_12h57_21.png

 

To verify further, access the Windows server where EMS is installed, run the command prompt as admin, and execute the commands below:


FcmUpdateDaemon.exe -e 

 

2024-05-02_13h02_57.png

 

The results will show if problems occurred while connecting to the above addresses.

  

Secondly, If allowed traffic was allowed to those domains, change FortiGuard servers with Global/US/Europe and try again. To do so,
Go to EMS -> Endpoint Profiles -> System Settings Profile -> Update.

 

2024-05-02_13h07_36.png

 

Go to EMS -> System Settings -> FortiGuard Services.


2024-05-02_13h06_35.png


See Required services and ports - FortiClient EMS administration guide.

Lastly, check if the 'Enable SSL' option under EMS -> System Settings -> FortiGuard Services is enabled, then check again by disabling it.

 

2024-05-02_13h21_58.png

 

If the issue improves after turning off the Enable SSL option, to restore the functionality of the Enable SSL option, raise a new ticket to the TAC team.