Installing a FortiEDR Collector on a Mac Operating System
To install a FortiEDR Collector on a Mac operating system that is running with Big Sur (version 11) or above:
The process described below includes a description of how to allow the following upon first FortiEDR Collector installation:
- System Extensions
- Network Extensions
- Full Disk Access
IMPORTANT: Failure to add these permissions will result in incomplete protection.
Deployment can also be managed using an MDM, such as Jamf.
- Double-click the *.dmg file named FortiEDRCollectorInstallerOSX_4.1.x.dmg.
-
Click Continue. -
Click Install. Enter the Mac password at the prompt. -
In the Collector Conifguration page, specify the Aggregator's address and FortiEDR registration password. Optionally, you can select a desitination Organization and Collector Group and/or installation using a system proxy.
- Click Apply to start the installation process.
- Perform the following during installation:
- Enable Network and System Extensions, shown below:
- Open Security Preferences.
- Click the lock at the bottom of the window in order to make changes.
- In the General tab, click Details.
Mark both checkboxes in order to allow FortiEDR to use Netword and System Extensions.- Click OK in the System Extension Blocked Window.
- Enable Full Disk Access by performing the following:
- Open Security Preferences.
- Click the lock at the bottom of the window in order to make changes.
- In the Privacy tab, select Full Disk Access from the left pane.
- Mark the checkboxes of both the FortiEDRCollector (FortiEDR in MacOS v11.3 and below) and the FortiEDR_EndPoint applications:
- If that FortiEDR application does not display on this page, click the + button.
Click Applications, select FortiEDR and then click Open.
- Enable Network and System Extensions, shown below:
-
In the popup window, click Later. -
Click Allow. -
Click OK. - Click Close to complete the process.
- When prompted to allow FORTIEDRTRAY notifications, click Allow
- Reboot the device.
- You can run the following command to check the status of the Collector:
/Applications/FortiEDR.app/fortiedr_collector.sh status
To install a FortiEDR Collector on a Mac- operating system with versions prior to Big Sur (11), such as Catalina or Mojave:
- Double-click the *.dmg file named FortiEDRCollectorInstallerOSX_1.3.0.xxx.dmg.
-
Double-click the *.pkg file named FortiEDRCollectorInstallerOSX_1.3.0.xxx.pkg -
Click Continue - Select the destination disk and click Continue
-
Specify the installation location and click Install -
In the Aggregator Address field, enter the IP address of the Aggregator in the first box and the port of the Aggregator in the adjacent (Port) box. - In the Registration Password field, enter the registration password as described in Launching the FortiEDR Central Manager for the First Time.
- Leave the Organization field empty or for a multi-tenant setup, insert the organization to which this Collector belongs (as it appears under the ADMINISTRATION > ORGANIZATIONS tab of the FortiEDR Central Manager).
- If you use a web proxy to filter requests in this device’s network, then check the Use System Proxy Settings checkbox. Note that the MacOS must be configured to use a proxy and that the proxy must support HTTPS before installing the Collector (System Preferences > Network > Advanced > Proxies).
- Click Apply.
-
Click Close.