FortiClient EMS + VPN / ZTNA
Basic Information
| Field | Value |
|---|---|
| Category | Infrastructure |
| Owner | Filip Kohák |
| Deputy | Artem Ryzhkov |
| SLA | 8x5 |
| Deployment | Hybrid (FortiEMS VM on Proxmox + FortiGate gateway) |
Description
FortiClient EMS (Endpoint Management Server) manages FortiClient agents installed on corporate devices. It provides remote access (VPN) and is the foundation for ZTNA (Zero Trust Network Access).
Current status:
- Remote access runs in parallel on OpenVPN (Viscosity) and FortiClient SSL-VPN
- ZTNA is in pilot phase — planned migration from OpenVPN
- FortiClient agents are distributed via Hexnode MDM on Mac devices
Procedure — Connect to VPN (for users)
SSL-VPN via FortiClient
- Open FortiClient app on your device
- Remote Access → VPN tab
- Select Etnetera SSL-VPN profile
- Log in with corporate credentials (AD or Entra ID)
- Complete MFA prompt (Microsoft Authenticator or FortiToken)
Fallback via OpenVPN (Viscosity)
- Open Viscosity from the menu bar
- Click Etnetera-VPN profile
- Enter AD credentials
- Connection establishes automatically
Tip
FortiClient VPN is preferred for new devices. OpenVPN (Viscosity) is the fallback and will be phased out.
Troubleshooting
| Problem | Solution |
|---|---|
| VPN won't connect | Check credentials; verify MFA; check FortiGate VPN port availability |
| FortiClient offline in EMS | Check device network connectivity to FortiEMS; restart FortiClient agent |
| Compliance check failing | Check AV (ESET) and disk encryption (FileVault/BitLocker) status on device |
| Slow VPN connection | Check split tunneling settings; verify ISP link status on FortiGate |
Planned Migration
- Goal: full migration from OpenVPN to FortiClient SSL-VPN / ZTNA
- Track progress in Jira project IT-INFRA
Related Guides
- FortiGate — VPN gateway, ZTNA access proxy
- Hexnode MDM — FortiClient distribution to Macs
- Active Directory — VPN user authentication
Contact
- Owner: Filip Kohák — Slack
@filip - Deputy: Artem Ryzhkov — Slack
@artem - VPN issues: Slack
#it-help