config endpoint-control fctems
Configure FortiClient Enterprise Management Server (EMS) entries.
config endpoint-control fctems Description: Configure FortiClient Enterprise Management Server (EMS) entries. edit <ems-id> set status [enable|disable] set name {string} set dirty-reason [none|mismatched-ems-sn] set fortinetone-cloud-authentication [enable|disable] set cloud-authentication-access-key {string} set server {string} set https-port {integer} set serial-number {string} set tenant-id {string} set source-ip {ipv4-address-any} set pull-sysinfo [enable|disable] set pull-vulnerabilities [enable|disable] set pull-avatars [enable|disable] set pull-tags [enable|disable] set pull-malware-hash [enable|disable] set capabilities {option1}, {option2}, ... set call-timeout {integer} set out-of-sync-threshold {integer} set send-tags-to-all-vdoms [enable|disable] set websocket-override [enable|disable] set preserve-ssl-session [enable|disable] set interface-select-method [auto|specify] set interface {string} set trust-ca-cn [enable|disable] set verifying-ca {string} next end
config endpoint-control fctems
Parameter |
Description |
Type |
Size |
Default |
||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ems-id |
EMS ID in order. |
integer |
Minimum value: 1 Maximum value: 7 |
0 |
||||||||||||||||||||||||
status |
Enable or disable this EMS configuration. |
option |
- |
disable |
||||||||||||||||||||||||
|
|
|||||||||||||||||||||||||||
name |
FortiClient Enterprise Management Server (EMS) name. |
string |
Maximum length: 35 |
|
||||||||||||||||||||||||
dirty-reason |
Dirty Reason for FortiClient EMS. |
option |
- |
none |
||||||||||||||||||||||||
|
|
|||||||||||||||||||||||||||
fortinetone-cloud-authentication |
Enable/disable authentication of FortiClient EMS Cloud through FortiCloud account. |
option |
- |
disable |
||||||||||||||||||||||||
|
|
|||||||||||||||||||||||||||
cloud-authentication-access-key |
FortiClient EMS Cloud multitenancy access key |
string |
Maximum length: 20 |
|
||||||||||||||||||||||||
server |
FortiClient EMS FQDN or IPv4 address. |
string |
Maximum length: 255 |
|
||||||||||||||||||||||||
https-port |
FortiClient EMS HTTPS access port number.. |
integer |
Minimum value: 1 Maximum value: 65535 |
443 |
||||||||||||||||||||||||
serial-number |
EMS Serial Number. |
string |
Maximum length: 16 |
|
||||||||||||||||||||||||
tenant-id |
EMS Tenant ID. |
string |
Maximum length: 32 |
|
||||||||||||||||||||||||
source-ip |
REST API call source IP. |
ipv4-address-any |
Not Specified |
0.0.0.0 |
||||||||||||||||||||||||
pull-sysinfo |
Enable/disable pulling SysInfo from EMS. |
option |
- |
enable |
||||||||||||||||||||||||
|
|
|||||||||||||||||||||||||||
pull-vulnerabilities |
Enable/disable pulling vulnerabilities from EMS. |
option |
- |
enable |
||||||||||||||||||||||||
|
|
|||||||||||||||||||||||||||
pull-avatars |
Enable/disable pulling avatars from EMS. |
option |
- |
enable |
||||||||||||||||||||||||
|
|
|||||||||||||||||||||||||||
pull-tags |
Enable/disable pulling FortiClient user tags from EMS. |
option |
- |
enable |
||||||||||||||||||||||||
|
|
|||||||||||||||||||||||||||
pull-malware-hash |
Enable/disable pulling FortiClient malware hash from EMS. |
option |
- |
enable |
||||||||||||||||||||||||
|
|
|||||||||||||||||||||||||||
capabilities |
List of EMS capabilities. |
option |
- |
|
||||||||||||||||||||||||
|
|
|||||||||||||||||||||||||||
call-timeout |
FortiClient EMS call timeout in seconds. |
integer |
Minimum value: 1 Maximum value: 180 |
30 |
||||||||||||||||||||||||
out-of-sync-threshold |
Outdated resource threshold in seconds. |
integer |
Minimum value: 10 Maximum value: 3600 |
180 |
||||||||||||||||||||||||
send-tags-to-all-vdoms |
Relax restrictions on tags to send all EMS tags to all VDOMs |
option |
- |
disable |
||||||||||||||||||||||||
|
|
|||||||||||||||||||||||||||
websocket-override |
Enable/disable override behavior for how this FortiProxy unit connects to EMS using a WebSocket connection. |
option |
- |
disable |
||||||||||||||||||||||||
|
|
|||||||||||||||||||||||||||
preserve-ssl-session |
Enable/disable preservation of EMS SSL session connection. Warning, most users should not touch this setting. |
option |
- |
disable |
||||||||||||||||||||||||
|
|
|||||||||||||||||||||||||||
interface-select-method |
Specify how to select outgoing interface to reach server. |
option |
- |
auto |
||||||||||||||||||||||||
|
|
|||||||||||||||||||||||||||
interface |
Specify outgoing interface to reach server. |
string |
Maximum length: 15 |
|
||||||||||||||||||||||||
trust-ca-cn |
Enable/disable trust of the EMS certificate issuer(CA) and common name(CN) for certificate auto-renewal. |
option |
- |
enable |
||||||||||||||||||||||||
|
|
|||||||||||||||||||||||||||
verifying-ca |
Lowest CA cert on Fortigate in verified EMS cert chain. |
string |
Maximum length: 79 |
|