Fortinet white logo
Fortinet white logo

CLI Reference

config endpoint-control fctems

config endpoint-control fctems

Configure FortiClient Enterprise Management Server (EMS) entries.

config endpoint-control fctems
    Description: Configure FortiClient Enterprise Management Server (EMS) entries.
    edit <ems-id>
        set status [enable|disable]
        set name {string}
        set dirty-reason [none|mismatched-ems-sn]
        set fortinetone-cloud-authentication [enable|disable]
        set cloud-authentication-access-key {string}
        set server {string}
        set https-port {integer}
        set serial-number {string}
        set tenant-id {string}
        set source-ip {ipv4-address-any}
        set pull-sysinfo [enable|disable]
        set pull-vulnerabilities [enable|disable]
        set pull-avatars [enable|disable]
        set pull-tags [enable|disable]
        set pull-malware-hash [enable|disable]
        set capabilities {option1}, {option2}, ...
        set call-timeout {integer}
        set out-of-sync-threshold {integer}
        set send-tags-to-all-vdoms [enable|disable]
        set websocket-override [enable|disable]
        set preserve-ssl-session [enable|disable]
        set interface-select-method [auto|specify]
        set interface {string}
        set trust-ca-cn [enable|disable]
        set verifying-ca {string}
    next
end

config endpoint-control fctems

Parameter

Description

Type

Size

Default

ems-id

EMS ID in order.

integer

Minimum value: 1 Maximum value: 7

0

status

Enable or disable this EMS configuration.

option

-

disable

Option

Description

enable

Enable EMS configuration and operation.

disable

Disable EMS configuration and operation.

name

FortiClient Enterprise Management Server (EMS) name.

string

Maximum length: 35

dirty-reason

Dirty Reason for FortiClient EMS.

option

-

none

Option

Description

none

FortiClient EMS entry not dirty.

mismatched-ems-sn

FortiClient EMS entry dirty because EMS SN is mismatched with configured SN.

fortinetone-cloud-authentication

Enable/disable authentication of FortiClient EMS Cloud through FortiCloud account.

option

-

disable

Option

Description

enable

Enable authentication of FortiClient EMS Cloud through FortiCloud account.

disable

Disable authentication of FortiClient EMS Cloud through FortiCloud account.

cloud-authentication-access-key

FortiClient EMS Cloud multitenancy access key

string

Maximum length: 20

server

FortiClient EMS FQDN or IPv4 address.

string

Maximum length: 255

https-port

FortiClient EMS HTTPS access port number..

integer

Minimum value: 1 Maximum value: 65535

443

serial-number

EMS Serial Number.

string

Maximum length: 16

tenant-id

EMS Tenant ID.

string

Maximum length: 32

source-ip

REST API call source IP.

ipv4-address-any

Not Specified

0.0.0.0

pull-sysinfo

Enable/disable pulling SysInfo from EMS.

option

-

enable

Option

Description

enable

Enable pulling FortiClient user SysInfo from EMS.

disable

Disable pulling FortiClient user SysInfo from EMS.

pull-vulnerabilities

Enable/disable pulling vulnerabilities from EMS.

option

-

enable

Option

Description

enable

Enable pulling client vulnerabilities from EMS.

disable

Disable pulling client vulnerabilities from EMS.

pull-avatars

Enable/disable pulling avatars from EMS.

option

-

enable

Option

Description

enable

Enable pulling FortiClient user avatars from EMS.

disable

Disable pulling FortiClient user avatars from EMS.

pull-tags

Enable/disable pulling FortiClient user tags from EMS.

option

-

enable

Option

Description

enable

Enable pulling FortiClient user tags from EMS.

disable

Disable pulling FortiClient user tags from EMS.

pull-malware-hash

Enable/disable pulling FortiClient malware hash from EMS.

option

-

enable

Option

Description

enable

Enable pulling FortiClient malware hash from EMS.

disable

Disable pulling FortiClient malware hash from EMS.

capabilities

List of EMS capabilities.

option

-

Option

Description

fabric-auth

Allow this FortiProxy unit to load the authentication page provided by EMS to authenticate itself with EMS.

silent-approval

Allow silent approval of non-root or FortiProxy HA clusters on EMS in the Security Fabric.

websocket

Enable/disable websockets for this FortiProxy unit. Override behavior using websocket-override.

websocket-malware

Allow this FortiGate unit to request malware hash notifications over websocket.

push-ca-certs

Enable/disable syncing deep inspection certificates with EMS.

common-tags-api

Can recieve tag information from New Common Tags API from EMS.

tenant-id

Allow this FortiGate to retrieve Tenant-ID from EMS.

client-avatars

Allow this FortiGate to retrieve avatars from EMS by fingerprint.

single-vdom-connector

Allow this FortiGate to create a vdom connector to EMS.

fgt-sysinfo-api

Allow this FortiGate to send additional info to EMS.

ztna-server-info

Allow this FortiGate to send vdom's ZTNA server information to EMS.

call-timeout

FortiClient EMS call timeout in seconds.

integer

Minimum value: 1 Maximum value: 180

30

out-of-sync-threshold

Outdated resource threshold in seconds.

integer

Minimum value: 10 Maximum value: 3600

180

send-tags-to-all-vdoms

Relax restrictions on tags to send all EMS tags to all VDOMs

option

-

disable

Option

Description

enable

Enable sending tags to all vdoms.

disable

Disable sending tags to all vdoms.

websocket-override

Enable/disable override behavior for how this FortiProxy unit connects to EMS using a WebSocket connection.

option

-

disable

Option

Description

enable

Do not override the WebSocket connection. Connect to WebSocket of this EMS server if it is capable (default).

disable

Override the WebSocket connection. Do not connect to WebSocket even if EMS is capable of a WebSocket connection.

preserve-ssl-session

Enable/disable preservation of EMS SSL session connection. Warning, most users should not touch this setting.

option

-

disable

Option

Description

enable

Allow preservation of EMS SSL session connection.

disable

Don't allow preservation of EMS SSL session connection.

interface-select-method

Specify how to select outgoing interface to reach server.

option

-

auto

Option

Description

auto

Set outgoing interface automatically.

specify

Set outgoing interface manually.

interface

Specify outgoing interface to reach server.

string

Maximum length: 15

trust-ca-cn

Enable/disable trust of the EMS certificate issuer(CA) and common name(CN) for certificate auto-renewal.

option

-

enable

Option

Description

enable

Trust EMS certificate CA & CN to automatically renew certificate.

disable

Do not trust EMS certificate CA & CN to automatically renew certificate.

verifying-ca

Lowest CA cert on Fortigate in verified EMS cert chain.

string

Maximum length: 79

config endpoint-control fctems

config endpoint-control fctems

Configure FortiClient Enterprise Management Server (EMS) entries.

config endpoint-control fctems
    Description: Configure FortiClient Enterprise Management Server (EMS) entries.
    edit <ems-id>
        set status [enable|disable]
        set name {string}
        set dirty-reason [none|mismatched-ems-sn]
        set fortinetone-cloud-authentication [enable|disable]
        set cloud-authentication-access-key {string}
        set server {string}
        set https-port {integer}
        set serial-number {string}
        set tenant-id {string}
        set source-ip {ipv4-address-any}
        set pull-sysinfo [enable|disable]
        set pull-vulnerabilities [enable|disable]
        set pull-avatars [enable|disable]
        set pull-tags [enable|disable]
        set pull-malware-hash [enable|disable]
        set capabilities {option1}, {option2}, ...
        set call-timeout {integer}
        set out-of-sync-threshold {integer}
        set send-tags-to-all-vdoms [enable|disable]
        set websocket-override [enable|disable]
        set preserve-ssl-session [enable|disable]
        set interface-select-method [auto|specify]
        set interface {string}
        set trust-ca-cn [enable|disable]
        set verifying-ca {string}
    next
end

config endpoint-control fctems

Parameter

Description

Type

Size

Default

ems-id

EMS ID in order.

integer

Minimum value: 1 Maximum value: 7

0

status

Enable or disable this EMS configuration.

option

-

disable

Option

Description

enable

Enable EMS configuration and operation.

disable

Disable EMS configuration and operation.

name

FortiClient Enterprise Management Server (EMS) name.

string

Maximum length: 35

dirty-reason

Dirty Reason for FortiClient EMS.

option

-

none

Option

Description

none

FortiClient EMS entry not dirty.

mismatched-ems-sn

FortiClient EMS entry dirty because EMS SN is mismatched with configured SN.

fortinetone-cloud-authentication

Enable/disable authentication of FortiClient EMS Cloud through FortiCloud account.

option

-

disable

Option

Description

enable

Enable authentication of FortiClient EMS Cloud through FortiCloud account.

disable

Disable authentication of FortiClient EMS Cloud through FortiCloud account.

cloud-authentication-access-key

FortiClient EMS Cloud multitenancy access key

string

Maximum length: 20

server

FortiClient EMS FQDN or IPv4 address.

string

Maximum length: 255

https-port

FortiClient EMS HTTPS access port number..

integer

Minimum value: 1 Maximum value: 65535

443

serial-number

EMS Serial Number.

string

Maximum length: 16

tenant-id

EMS Tenant ID.

string

Maximum length: 32

source-ip

REST API call source IP.

ipv4-address-any

Not Specified

0.0.0.0

pull-sysinfo

Enable/disable pulling SysInfo from EMS.

option

-

enable

Option

Description

enable

Enable pulling FortiClient user SysInfo from EMS.

disable

Disable pulling FortiClient user SysInfo from EMS.

pull-vulnerabilities

Enable/disable pulling vulnerabilities from EMS.

option

-

enable

Option

Description

enable

Enable pulling client vulnerabilities from EMS.

disable

Disable pulling client vulnerabilities from EMS.

pull-avatars

Enable/disable pulling avatars from EMS.

option

-

enable

Option

Description

enable

Enable pulling FortiClient user avatars from EMS.

disable

Disable pulling FortiClient user avatars from EMS.

pull-tags

Enable/disable pulling FortiClient user tags from EMS.

option

-

enable

Option

Description

enable

Enable pulling FortiClient user tags from EMS.

disable

Disable pulling FortiClient user tags from EMS.

pull-malware-hash

Enable/disable pulling FortiClient malware hash from EMS.

option

-

enable

Option

Description

enable

Enable pulling FortiClient malware hash from EMS.

disable

Disable pulling FortiClient malware hash from EMS.

capabilities

List of EMS capabilities.

option

-

Option

Description

fabric-auth

Allow this FortiProxy unit to load the authentication page provided by EMS to authenticate itself with EMS.

silent-approval

Allow silent approval of non-root or FortiProxy HA clusters on EMS in the Security Fabric.

websocket

Enable/disable websockets for this FortiProxy unit. Override behavior using websocket-override.

websocket-malware

Allow this FortiGate unit to request malware hash notifications over websocket.

push-ca-certs

Enable/disable syncing deep inspection certificates with EMS.

common-tags-api

Can recieve tag information from New Common Tags API from EMS.

tenant-id

Allow this FortiGate to retrieve Tenant-ID from EMS.

client-avatars

Allow this FortiGate to retrieve avatars from EMS by fingerprint.

single-vdom-connector

Allow this FortiGate to create a vdom connector to EMS.

fgt-sysinfo-api

Allow this FortiGate to send additional info to EMS.

ztna-server-info

Allow this FortiGate to send vdom's ZTNA server information to EMS.

call-timeout

FortiClient EMS call timeout in seconds.

integer

Minimum value: 1 Maximum value: 180

30

out-of-sync-threshold

Outdated resource threshold in seconds.

integer

Minimum value: 10 Maximum value: 3600

180

send-tags-to-all-vdoms

Relax restrictions on tags to send all EMS tags to all VDOMs

option

-

disable

Option

Description

enable

Enable sending tags to all vdoms.

disable

Disable sending tags to all vdoms.

websocket-override

Enable/disable override behavior for how this FortiProxy unit connects to EMS using a WebSocket connection.

option

-

disable

Option

Description

enable

Do not override the WebSocket connection. Connect to WebSocket of this EMS server if it is capable (default).

disable

Override the WebSocket connection. Do not connect to WebSocket even if EMS is capable of a WebSocket connection.

preserve-ssl-session

Enable/disable preservation of EMS SSL session connection. Warning, most users should not touch this setting.

option

-

disable

Option

Description

enable

Allow preservation of EMS SSL session connection.

disable

Don't allow preservation of EMS SSL session connection.

interface-select-method

Specify how to select outgoing interface to reach server.

option

-

auto

Option

Description

auto

Set outgoing interface automatically.

specify

Set outgoing interface manually.

interface

Specify outgoing interface to reach server.

string

Maximum length: 15

trust-ca-cn

Enable/disable trust of the EMS certificate issuer(CA) and common name(CN) for certificate auto-renewal.

option

-

enable

Option

Description

enable

Trust EMS certificate CA & CN to automatically renew certificate.

disable

Do not trust EMS certificate CA & CN to automatically renew certificate.

verifying-ca

Lowest CA cert on Fortigate in verified EMS cert chain.

string

Maximum length: 79