Fortinet white logo
Fortinet white logo

Special notices

Special notices

FortiClient EMS Microsoft Visual C++ installation

The EMS installation includes installation of Microsoft Visual C++ (VC) 2015. If the server already has a newer version of VC installed, the installation fails. See VC++ 2015 Redistributable installation returns error 1638 when newer version already installed.

If you have a version of VC installed on your server that is newer than 2015, uninstall VC before installing EMS.

SQL Server Standard or Enterprise with 5000 or more endpoints

When managing more than 5000 endpoints, install SQL Server Standard or Enterprise instead of SQL Server Express, which the EMS installation also installs by default. Otherwise, you may experience database deadlocks. The minimum SQL Server version that FortiClient EMS supports is 2017. See the FortiClient EMS Administration Guide.

Split tunnel

In EMS 7.0.6, you configure application split tunnel using per-tunnel configuration, not a global configuration. If you are upgrading from an older version that uses the global application split tunnel configuration, ensure that you change the configuration to per-tunnel.

Sending Web Filter logs to FortiAnalyzer

Due to an issue where FortiClient (Windows) does not send Web Filter logs to FortiAnalyzer, EMS has removed the four default wanacc shield scheduler configd settings after saving the system profile from the GUI.

Until this issue is resolved, for FortiClient to send traffic logs to FortiAnalyzer, ensure to configure the following settings:

  • Enable the log event setting for the scheduler in the EMS System Settings profile: <log_events>...,scheduler,...</log_events>. Scheduler log events include all events with subtype="system" in the log definition file defined in each CM build, for example: https://info.fortinet.com/files/FortiClient/v7.00/images/build0238/fct_log_def_7.0.5.0238.xml.
  • Enable the webfilter log_all_urls setting. When log_all_urls is enabled, FortiClient logs all traffic URLs, including passthrough traffic for all features, such as Web Filter, VPN, antivirus, and so on.

Special notices

Special notices

FortiClient EMS Microsoft Visual C++ installation

The EMS installation includes installation of Microsoft Visual C++ (VC) 2015. If the server already has a newer version of VC installed, the installation fails. See VC++ 2015 Redistributable installation returns error 1638 when newer version already installed.

If you have a version of VC installed on your server that is newer than 2015, uninstall VC before installing EMS.

SQL Server Standard or Enterprise with 5000 or more endpoints

When managing more than 5000 endpoints, install SQL Server Standard or Enterprise instead of SQL Server Express, which the EMS installation also installs by default. Otherwise, you may experience database deadlocks. The minimum SQL Server version that FortiClient EMS supports is 2017. See the FortiClient EMS Administration Guide.

Split tunnel

In EMS 7.0.6, you configure application split tunnel using per-tunnel configuration, not a global configuration. If you are upgrading from an older version that uses the global application split tunnel configuration, ensure that you change the configuration to per-tunnel.

Sending Web Filter logs to FortiAnalyzer

Due to an issue where FortiClient (Windows) does not send Web Filter logs to FortiAnalyzer, EMS has removed the four default wanacc shield scheduler configd settings after saving the system profile from the GUI.

Until this issue is resolved, for FortiClient to send traffic logs to FortiAnalyzer, ensure to configure the following settings:

  • Enable the log event setting for the scheduler in the EMS System Settings profile: <log_events>...,scheduler,...</log_events>. Scheduler log events include all events with subtype="system" in the log definition file defined in each CM build, for example: https://info.fortinet.com/files/FortiClient/v7.00/images/build0238/fct_log_def_7.0.5.0238.xml.
  • Enable the webfilter log_all_urls setting. When log_all_urls is enabled, FortiClient logs all traffic URLs, including passthrough traffic for all features, such as Web Filter, VPN, antivirus, and so on.