Fortinet black logo

EMS Administration Guide

Importing FortiGate profiles

Importing FortiGate profiles

In FortiOS, endpoint profiles are called FortiClient Compliance profiles. You can import a FortiClient Compliance profile into EMS, then edit the profile in FortiClient EMS to add a FortiClient installer or add configuration information that supports the FortiGate compliance rules.

To import profiles successfully from FortiOS to FortiClient EMS, FortiGate must have the HTTPS port open. In FortiOS, go to Network > Interfaces > Administrative Access and enable the HTTPS checkbox.

To import profiles:
  1. Click Endpoint Profiles > Manage Profiles > Import. The Import Profiles from FortiGate/FortiManager window opens.

  2. Under Type, select FortiGate.
  3. Complete the following options, and click Next.

    IP address/Hostname

    Enter the IP address and port of the FortiGate device from which the profile is being imported, in the format: <ip address>:<port>.

    VDOM

    Enter a VDOM name from the FortiGate if applicable.

    Username

    Enter the FortiGate's login username.

    Password

    Enter the FortiGate's login password.

    The list of FortiClient Compliance profiles configured on the FortiGate displays.

    Under each profile name is the list of profiles created for different operating systems, such as desktops running a Windows or Mac operating system or devices running an Android operating system. In the example, under the test profile, Android, Desktop, and iOS profiles are listed. You can click the </> icon beside each profile to preview the settings in XML format.

  4. Select the profiles to import into EMS and click Next.

    Select the name of the profile to import all profiles for it into EMS. You can also clear the checkbox beside the profiles you do not want to import into EMS. For example, you can import the Android and desktop profiles, but not the iOS profile for a given profile name.

  5. Under Synchronization Mode, select one of the following options.

    1. One Time Pull: If selected, FortiClient EMS does not automatically sync profile changes from the FortiGate. You can manually sync profile changes after importing the profile. See Syncing profile changes.
    2. Group Schedule: Select to configure a group synchronization schedule for all selected profiles. Select the next date and time to automatically update the profiles, and the profile update interval in days, hours, or seconds.
    3. Individual Schedule: Select to configure an individual synchronization schedule for each selected profile. Select the next date and time to automatically update each profile, and the profile update interval in days, hours, or seconds.
  6. Click Import. The selected profiles are imported into EMS and display under the Endpoint Profiles pane in a group named after the FortiGate device from which they were imported.
  7. In the Endpoint Profiles page, select an imported profile to edit it.

    The options configured in the profile by the FortiGate administrator are read-only compliance rules. You cannot change them. You can edit additional options to provide configuration information to support the compliance rules. You can also add a FortiClient installer to the profile by using the Deployment tab. Custom installers can be created. See Adding FortiClient installers.

  8. Edit the options on the tabs.
  9. Click Save Profile.

Importing FortiGate profiles

In FortiOS, endpoint profiles are called FortiClient Compliance profiles. You can import a FortiClient Compliance profile into EMS, then edit the profile in FortiClient EMS to add a FortiClient installer or add configuration information that supports the FortiGate compliance rules.

To import profiles successfully from FortiOS to FortiClient EMS, FortiGate must have the HTTPS port open. In FortiOS, go to Network > Interfaces > Administrative Access and enable the HTTPS checkbox.

To import profiles:
  1. Click Endpoint Profiles > Manage Profiles > Import. The Import Profiles from FortiGate/FortiManager window opens.

  2. Under Type, select FortiGate.
  3. Complete the following options, and click Next.

    IP address/Hostname

    Enter the IP address and port of the FortiGate device from which the profile is being imported, in the format: <ip address>:<port>.

    VDOM

    Enter a VDOM name from the FortiGate if applicable.

    Username

    Enter the FortiGate's login username.

    Password

    Enter the FortiGate's login password.

    The list of FortiClient Compliance profiles configured on the FortiGate displays.

    Under each profile name is the list of profiles created for different operating systems, such as desktops running a Windows or Mac operating system or devices running an Android operating system. In the example, under the test profile, Android, Desktop, and iOS profiles are listed. You can click the </> icon beside each profile to preview the settings in XML format.

  4. Select the profiles to import into EMS and click Next.

    Select the name of the profile to import all profiles for it into EMS. You can also clear the checkbox beside the profiles you do not want to import into EMS. For example, you can import the Android and desktop profiles, but not the iOS profile for a given profile name.

  5. Under Synchronization Mode, select one of the following options.

    1. One Time Pull: If selected, FortiClient EMS does not automatically sync profile changes from the FortiGate. You can manually sync profile changes after importing the profile. See Syncing profile changes.
    2. Group Schedule: Select to configure a group synchronization schedule for all selected profiles. Select the next date and time to automatically update the profiles, and the profile update interval in days, hours, or seconds.
    3. Individual Schedule: Select to configure an individual synchronization schedule for each selected profile. Select the next date and time to automatically update each profile, and the profile update interval in days, hours, or seconds.
  6. Click Import. The selected profiles are imported into EMS and display under the Endpoint Profiles pane in a group named after the FortiGate device from which they were imported.
  7. In the Endpoint Profiles page, select an imported profile to edit it.

    The options configured in the profile by the FortiGate administrator are read-only compliance rules. You cannot change them. You can edit additional options to provide configuration information to support the compliance rules. You can also add a FortiClient installer to the profile by using the Deployment tab. Custom installers can be created. See Adding FortiClient installers.

  8. Edit the options on the tabs.
  9. Click Save Profile.