Fortinet black logo

Adding a FortiClient deployment package

Copy Link
Copy Doc ID 41f74845-9b80-11ee-a142-fa163e15d75b:942839
Download PDF

Adding a FortiClient deployment package

FortiClient Cloud allows a maximum of ten deployment packages.

To add a deployment package:
  1. Go to Manage Installers > Deployment Packages.
  2. Click Add.
  3. On the Version tab, set the following options:

    Installer Type

    Use an official FortiClient installer or a custom FortiClient installer. See Adding a custom FortiClient installer for details on uploading a custom installer.

    Release

    Select the FortiClient release version to install.

    Patch

    Select the specific FortiClient patch version to install.

    Keep updated to the latest patch

    Select to enable FortiClient to automatically update to the latest patch release when FortiClient is installed on an endpoint.

    Custom installer

    Select the desired custom FortiClient installer.

  4. Click Next. On the General tab, set the following options:

    Name

    Enter the FortiClient deployment package's name.

    Expiry DateEnter this deployment package's expiry date. After this date, users cannot use this deployment package to install FortiClient.

    Notes

    (Optional) Enter any notes about the FortiClient deployment package.

  5. Click Next. On the Features tab, set the following options:

    Security Fabric Agent

    Enabled by default and cannot be disabled. Installs FortiClient with Telemetry enabled.

    Secure Access Architecture Components

    Install FortiClient with SSL and IPsec VPN enabled. Disable to omit SSL and IPsec VPN support from the FortiClient deployment package.

    Advanced Persistent Threat (APT) Components

    Install FortiClient with APT components enabled. Disable to omit APT components from the FortiClient deployment package. Includes FortiSandbox detection and quarantine features.

    Additional Security Features

    Enable any of the following features:

    • AntiVirus
    • Web Filtering
    • Application Firewall
    • Single Sign-On (SSO) mobility agent
    • Cloud Based Malware Outbreak Detection

    Disable to exclude features from the FortiClient deployment package.

    Note

    FortiClient Cloud does not support all the features that an on-premise EMS supports. See Limitations.

  6. Click Next. On the Advanced tab, set the following options:

    Enable automatic registration

    FortiClient automatically connects Telemetry to FortiClient after FortiClient installs on the endpoint. You cannot disable this option.

    Enable desktop shortcut

    Configure the FortiClient deployment package to create a desktop shortcut on the endpoint.

    Enable start menu shortcut

    Configure the FortiClient deployment package to create a Start menu shortcut on the endpoint.

    Enable Installer ID

    Configure an installer ID. Select an existing installer ID or enter a new installer ID. If creating an installer ID, select a group path or create a new group in the Group Path field. FortiClient automatically groups endpoints according to installer ID group assignment rules.

    Enable Endpoint Profile

    Select an endpoint profile to include in the installer. EMS applies the profile to the endpoint once it has installed FortiClient. This option is necessary if it is required to have certain security features enabled prior to contact with EMS, or if users require VPN connection to connect to EMS.

  7. Click Next. The Telemetry tab displays the hostname and IP address of the FortiClient server, which will manage FortiClient once it is installed on the endpoint. Also configure the following option:

    Enable telemetry connection to Security Fabric (FortiGate)

    Enable this option, and select the name of the gateway list to use. The gateway list defines the IP address for the FortiGate.

    If you have not created a gateway list, select the checkbox, then click the No telemetry server lists are available, create one here link to create a gateway list for this deployment package to use. See FortiClient EMS Administration Guide for details on configuring a gateway list.

  8. Click Finish. The FortiClient deployment package is added to FortiClient and displays on the Manage Installers > Deployment Packages pane. The deployment package may include .exe (32-bit and 64-bit), .msi, and .dmg files depending on the configuration.

Adding a FortiClient deployment package

FortiClient Cloud allows a maximum of ten deployment packages.

To add a deployment package:
  1. Go to Manage Installers > Deployment Packages.
  2. Click Add.
  3. On the Version tab, set the following options:

    Installer Type

    Use an official FortiClient installer or a custom FortiClient installer. See Adding a custom FortiClient installer for details on uploading a custom installer.

    Release

    Select the FortiClient release version to install.

    Patch

    Select the specific FortiClient patch version to install.

    Keep updated to the latest patch

    Select to enable FortiClient to automatically update to the latest patch release when FortiClient is installed on an endpoint.

    Custom installer

    Select the desired custom FortiClient installer.

  4. Click Next. On the General tab, set the following options:

    Name

    Enter the FortiClient deployment package's name.

    Expiry DateEnter this deployment package's expiry date. After this date, users cannot use this deployment package to install FortiClient.

    Notes

    (Optional) Enter any notes about the FortiClient deployment package.

  5. Click Next. On the Features tab, set the following options:

    Security Fabric Agent

    Enabled by default and cannot be disabled. Installs FortiClient with Telemetry enabled.

    Secure Access Architecture Components

    Install FortiClient with SSL and IPsec VPN enabled. Disable to omit SSL and IPsec VPN support from the FortiClient deployment package.

    Advanced Persistent Threat (APT) Components

    Install FortiClient with APT components enabled. Disable to omit APT components from the FortiClient deployment package. Includes FortiSandbox detection and quarantine features.

    Additional Security Features

    Enable any of the following features:

    • AntiVirus
    • Web Filtering
    • Application Firewall
    • Single Sign-On (SSO) mobility agent
    • Cloud Based Malware Outbreak Detection

    Disable to exclude features from the FortiClient deployment package.

    Note

    FortiClient Cloud does not support all the features that an on-premise EMS supports. See Limitations.

  6. Click Next. On the Advanced tab, set the following options:

    Enable automatic registration

    FortiClient automatically connects Telemetry to FortiClient after FortiClient installs on the endpoint. You cannot disable this option.

    Enable desktop shortcut

    Configure the FortiClient deployment package to create a desktop shortcut on the endpoint.

    Enable start menu shortcut

    Configure the FortiClient deployment package to create a Start menu shortcut on the endpoint.

    Enable Installer ID

    Configure an installer ID. Select an existing installer ID or enter a new installer ID. If creating an installer ID, select a group path or create a new group in the Group Path field. FortiClient automatically groups endpoints according to installer ID group assignment rules.

    Enable Endpoint Profile

    Select an endpoint profile to include in the installer. EMS applies the profile to the endpoint once it has installed FortiClient. This option is necessary if it is required to have certain security features enabled prior to contact with EMS, or if users require VPN connection to connect to EMS.

  7. Click Next. The Telemetry tab displays the hostname and IP address of the FortiClient server, which will manage FortiClient once it is installed on the endpoint. Also configure the following option:

    Enable telemetry connection to Security Fabric (FortiGate)

    Enable this option, and select the name of the gateway list to use. The gateway list defines the IP address for the FortiGate.

    If you have not created a gateway list, select the checkbox, then click the No telemetry server lists are available, create one here link to create a gateway list for this deployment package to use. See FortiClient EMS Administration Guide for details on configuring a gateway list.

  8. Click Finish. The FortiClient deployment package is added to FortiClient and displays on the Manage Installers > Deployment Packages pane. The deployment package may include .exe (32-bit and 64-bit), .msi, and .dmg files depending on the configuration.