Fortinet white logo
Fortinet white logo

Installing the FortiNBI application

Installing the FortiNBI application

When a FortiProxy user with a matching policy that has the isolator profile attempts to access a website on a machine without the FortiNBI service running, the user will see the following prompt page with a download link to the FortiNBI installer.

To install the FortiNBI application:
  1. Click the FortiNBI installer link on the browser isolation replacement page to download the installer.

  2. Run the installer with an administrator account:

    1. .NET Runtime 7.0 and Windows App SDK 1.4 are automatically installed. If the automatic installation fails, you must manually download and install these components from the Microsoft website:

    2. Files are unpacked to the installation folder, by default C:\Program Files (x86)\Fortinet\FortiNBI.

    3. The FortiNBI GUI is registered as a task that runs automatically every time that a user logs on.

  3. FortiNBI starts automatically, followed by isolator and extension installations:

    1. FortiNBI checks if the system has Windows Subsystem for Linux (WSL) and Virtual Machine Platform enabled. If not, the installer will automatically enable and configure it.

    2. The isolator image is downloaded from the FortiProxy's portal through HTTPS, extracted to a temporary folder, imported to the system, and then the temporary files are removed.

    3. After the installation procedure finishes, restart the browser (if the browser is already open) for the FNBI extension to be installed. Reboot Windows when requested.

    4. If using Firefox, the first time that you use FortiNBI you will see a prompt page with instructions to enable browser permissions to access site data. Follow the instructions to enable the browser permissions.

  4. When required, the client will receive an RDP pop-up window for isolation.

Upgrading FortiNBI

When a new FortiNBI version or isolator image is available, you can upgrade your FortiNBI or isolator image version without upgrading your FortiProxy:

  1. Upload the latest FortiNBI installer or isolator image to FortiProxy by running the following commands:

    • execute upload fortinbi-installer cloud
    • execute upload fortinbi-isolator-image cloud
  2. When the upload process is complete, verify the uploaded installer or image version by running diag wad nbi status.

  3. (FortiNBI installer) In Task Manager, restart FortiNBI.tating_service to trigger FortiProxy to automatically install the new version of FortiNBI application.

  4. (Isolator image) In the Status tab of the FortiNBI application, click Start in the Isolator row to trigger the installation of the new isolator image.

  5. Wait for the installation to complete and reboot the machine when requested.

  6. (FortiNBI installer) Verify the current FortiNBI version in the About tab of the FortiNBI application.

Installing the FortiNBI application

Installing the FortiNBI application

When a FortiProxy user with a matching policy that has the isolator profile attempts to access a website on a machine without the FortiNBI service running, the user will see the following prompt page with a download link to the FortiNBI installer.

To install the FortiNBI application:
  1. Click the FortiNBI installer link on the browser isolation replacement page to download the installer.

  2. Run the installer with an administrator account:

    1. .NET Runtime 7.0 and Windows App SDK 1.4 are automatically installed. If the automatic installation fails, you must manually download and install these components from the Microsoft website:

    2. Files are unpacked to the installation folder, by default C:\Program Files (x86)\Fortinet\FortiNBI.

    3. The FortiNBI GUI is registered as a task that runs automatically every time that a user logs on.

  3. FortiNBI starts automatically, followed by isolator and extension installations:

    1. FortiNBI checks if the system has Windows Subsystem for Linux (WSL) and Virtual Machine Platform enabled. If not, the installer will automatically enable and configure it.

    2. The isolator image is downloaded from the FortiProxy's portal through HTTPS, extracted to a temporary folder, imported to the system, and then the temporary files are removed.

    3. After the installation procedure finishes, restart the browser (if the browser is already open) for the FNBI extension to be installed. Reboot Windows when requested.

    4. If using Firefox, the first time that you use FortiNBI you will see a prompt page with instructions to enable browser permissions to access site data. Follow the instructions to enable the browser permissions.

  4. When required, the client will receive an RDP pop-up window for isolation.

Upgrading FortiNBI

When a new FortiNBI version or isolator image is available, you can upgrade your FortiNBI or isolator image version without upgrading your FortiProxy:

  1. Upload the latest FortiNBI installer or isolator image to FortiProxy by running the following commands:

    • execute upload fortinbi-installer cloud
    • execute upload fortinbi-isolator-image cloud
  2. When the upload process is complete, verify the uploaded installer or image version by running diag wad nbi status.

  3. (FortiNBI installer) In Task Manager, restart FortiNBI.tating_service to trigger FortiProxy to automatically install the new version of FortiNBI application.

  4. (Isolator image) In the Status tab of the FortiNBI application, click Start in the Isolator row to trigger the installation of the new isolator image.

  5. Wait for the installation to complete and reboot the machine when requested.

  6. (FortiNBI installer) Verify the current FortiNBI version in the About tab of the FortiNBI application.