Special notices
FortiClient on macOS Catalina (version 10.15)
You can install FortiClient (macOS) 6.4.2 on macOS 10.15 Catalina. With this macOS release, however, FortiClient works properly only when you grant permissions to access the full disk in the Security & Privacy pane for the following services:
- fcaptmon
- fctservctl
- fmon
- fmon2
- FortiClient
The fcaptmon, fmon, and fmon2 services are not included for the FortiClient (macOS) free VPN-only client. If you are using the VPN-only client, you only need to grant permissions for fctservctl and FortiClient.
You may have to manually add fmon2 to the list, as it may not be in the list of applications to allow full disk access to. Click the + icon to add an application. Browse to /Library/Application Support/Fortinet/FortiClient/bin/
and select fmon2.
The following lists the services and their folder locations:
-
fmon, Fctservctl, Fcaptmon:
/Library/Application\ Support/Fortinet/FortiClient/bin/
-
FortiClient (macOS) application:
/Applications/FortiClient.app
-
FortiClient agent (FortiTray):
/Applications/FortiClient.app/Contents/Resources/runtime.helper/FortiClientAgent.app
FortiClient Web Filter
The FortiClient (macOS) Web Filter feature works properly only when you allow system software from Fortinet to load in Security & Privacy settings. Go to System Preferences > Security & Privacy and click the Allow button beside System software from developer "Fortinet, Inc" was blocked from loading. You must have administrator credentials for the macOS machine to configure this change.
The FortiClient (macOS) team ID is AH4XFXJ7DK.
FortiClient (macOS) does not support Web Filter for websites using TLS 1.3.
DHCP over IPsec VPN not supported
FortiClient (macOS) does not support DHCP over IPsec VPN.
macOS Catalina (version 10.15) reboot prompt
When using macOS Catalina (version 10.15), you must reboot the macOS device after installing FortiClient (macOS). FortiClient (macOS) displays the following prompt after installation:
IKEv2 not supported
FortiClient (macOS) does not support IPsec VPN IKEv2.