Installing the FortiNBI application
When a FortiProxy user with a matching policy that has the isolator profile attempts to access a website on a machine without the FortiNBI service running, the user will see the following prompt page with a download link to the FortiNBI installer.
To install the FortiNBI application:
-
Click the FortiNBI installer link on the browser isolation replacement page to download the installer.
-
Run the installer with an administrator account:
-
.NET Runtime 7.0 and Windows App SDK 1.4 are automatically installed. If the automatic installation fails, you must manually download and install these components from the Microsoft website:
-
Files are unpacked to the installation folder, by default C:\Program Files (x86)\Fortinet\FortiNBI.
-
The FortiNBI GUI is registered as a task that runs automatically every time that a user logs on.
-
-
FortiNBI starts automatically, followed by isolator and extension installations:
-
FortiNBI checks if the system has Windows Subsystem for Linux (WSL) and Virtual Machine Platform enabled. If not, the installer will automatically enable and configure it.
-
The isolator image is downloaded from the FortiProxy's portal through HTTPS, extracted to a temporary folder, imported to the system, and then the temporary files are removed.
-
After the installation procedure finishes, restart the browser (if the browser is already open) for the FNBI extension to be installed. Reboot Windows when requested.
-
If using Firefox, the first time that you use FortiNBI you will see a prompt page with instructions to enable browser permissions to access site data. Follow the instructions to enable the browser permissions.
-
-
When required, the client will receive an RDP pop-up window for isolation.
Upgrading FortiNBI
When a new FortiNBI version or isolator image is available, you can upgrade your FortiNBI or isolator image version without upgrading your FortiProxy:
-
Upload the latest FortiNBI installer or isolator image to FortiProxy by running the following commands:
execute upload fortinbi-installer cloud
execute upload fortinbi-isolator-image cloud
-
When the upload process is complete, verify the uploaded installer or image version by running
diag wad nbi status
. -
(FortiNBI installer) In Task Manager, restart
FortiNBI.tating_service
to trigger FortiProxy to automatically install the new version of FortiNBI application. -
(Isolator image) In the Status tab of the FortiNBI application, click Start in the Isolator row to trigger the installation of the new isolator image.
-
Wait for the installation to complete and reboot the machine when requested.
-
(FortiNBI installer) Verify the current FortiNBI version in the About tab of the FortiNBI application.