On-fabric Detection Rules
You can configure on-fabric detection rules for endpoints. EMS uses the rules to determine if the endpoint is on- or off-fabric. Depending on the endpoint's on-fabric status, EMS may apply a different profile to the endpoint, as configured in the applied endpoint policy. See Adding an endpoint policy.
When a user switches accounts between a local non-domain account and a domain account on the same machine, FortiClient EMS may not apply the correct policy to the endpoint.
To add an on-fabric detection rule set:
- Go to Endpoint Policy & Components > On-fabric Detection Rules.
- Click Add.
- In the Name field, enter the desired name.
- Enable or disable the rule set by toggling Enabled on or off.
- Click Add Rule.
- In the Add New Rule dialog, from the Detection Type dropdown list, select and configure the desired rule detection type. If you configure rules of multiple detection types for a rule set, the endpoint must satisfy all configured rules to satisfy the entire rule set:
- Click Add Rule.
- Click Save.
To edit an on-fabric detection rule set:
- Go to Endpoint Policy & Components > On-fabric Detection Rules.
- Select the rule set.
- Click Edit.
- Edit as desired.
- Click Save.
To delete an on-fabric detection rule set:
- Go to Endpoint Policy & Components > On-fabric Detection Rules.
- Click the desired rule set.
- Click Delete.
- In the confirmation dialog, click Yes.
To delete an on-fabric detection rule from a rule set:
- Go to Endpoint Policy & Components > On-fabric Detection Rules.
- Click the desired rule set.
- Under Rules, select the desired rule.
- Click Delete Rule.
- Click Save.
To enable/disable an on-fabric detection rule:
- Go to Endpoint Policy & Components > On-fabric Detection Rules.
- Select or deselect the Enabled checkbox for the desired rule set.