Fortinet white logo
Fortinet white logo

Examples

Deploying FortiPAM CA using EMS

Deploying FortiPAM CA using EMS

To deploy FortiPAM CA using EMS:
  1. Connect FortiPAM to the EMS:
    1. Log in to FortiPAM.
    2. Go to Network > Fabric Connectors.
    3. In the Core Network Security pane, select FortiClient EMS and then select Edit.

      The New Fabric Connector pane opens.

    4. In Name, enter the name of the FortiClient EMS connector.
    5. In IP/Domain name, the IP address of the FortiClient EMS.
    6. In HTTPS port, enter the HTTPS port number for the FortiClient EMS.
    7. Ensure that EMS Threat Feed and Synchronize firewall addresses are enabled.
    8. Click OK.

      FortiPAM verifies the EMS server certificate.

  2. On the EMS GUI, deploy the FortiPAM default CA to FortiClient.
    1. Log in to the EMS GUI.
    2. Go Endpoint Policy & Components > CA Certificates.
    3. In the list, locate FortiPAM from step 1 using the serial number, e.g., FortiPAM serial number: FPAVULTM24001033.

    4. Go to Endpoint Profiles > System Setting.
    5. Select the corresponding profile and edit it.
    6. Go to the Others pane.

    7. Look for your FortiPAM serial number and enable Fortinet_CA_SSL.
    8. Click Save.

  3. Wait for a few minutes. All the Windows host with FortiClient belonging to Endpoint Profiles in step 2 are pushed and installed above the default FortiPAM CA certificate.

    If needed, run manage user certificate on Windows to check whether the CA certificate has been installed.

  4. After the FortiPAM CA certificate has been installed, you can launch the Web Account secret with Web Proxy enabled.

Deploying FortiPAM CA using EMS

Deploying FortiPAM CA using EMS

To deploy FortiPAM CA using EMS:
  1. Connect FortiPAM to the EMS:
    1. Log in to FortiPAM.
    2. Go to Network > Fabric Connectors.
    3. In the Core Network Security pane, select FortiClient EMS and then select Edit.

      The New Fabric Connector pane opens.

    4. In Name, enter the name of the FortiClient EMS connector.
    5. In IP/Domain name, the IP address of the FortiClient EMS.
    6. In HTTPS port, enter the HTTPS port number for the FortiClient EMS.
    7. Ensure that EMS Threat Feed and Synchronize firewall addresses are enabled.
    8. Click OK.

      FortiPAM verifies the EMS server certificate.

  2. On the EMS GUI, deploy the FortiPAM default CA to FortiClient.
    1. Log in to the EMS GUI.
    2. Go Endpoint Policy & Components > CA Certificates.
    3. In the list, locate FortiPAM from step 1 using the serial number, e.g., FortiPAM serial number: FPAVULTM24001033.

    4. Go to Endpoint Profiles > System Setting.
    5. Select the corresponding profile and edit it.
    6. Go to the Others pane.

    7. Look for your FortiPAM serial number and enable Fortinet_CA_SSL.
    8. Click Save.

  3. Wait for a few minutes. All the Windows host with FortiClient belonging to Endpoint Profiles in step 2 are pushed and installed above the default FortiPAM CA certificate.

    If needed, run manage user certificate on Windows to check whether the CA certificate has been installed.

  4. After the FortiPAM CA certificate has been installed, you can launch the Web Account secret with Web Proxy enabled.