Fortinet black logo

Administration Guide

Advanced options

Advanced options

To configure advanced options:
  1. Go to Settings, and expand the Advanced section.
  2. Configure the following settings, and click OK:

    Default tab

    Select the default tab to display when opening FortiClient.

    Action for EMS invalid certificates

    Select the action to take when FortiClient attempts to connect to EMS with an invalid certificate:

    • Warn: warn the user about the invalid server certificate. Ask the user whether to proceed with connecting to EMS, or terminate the connection attempt. FortiClient remembers the user's decision for this EMS, but displays the warning prompt if FortiClient attempts to connect to another EMS (using a different EMS FQDN/IP address and certificate) with an invalid certificate.
    • Allow: allows FortiClient to connect to EMS with an invalid certificate.
    • Deny: block FortiClient from connecting to EMS with an invalid certificate.

    Enable Single Sign-On mobility agent

    Enable SSO.

    Enable Privilege Access Management

    Enable privilege access management (PAM). This enables FortiClient to communicate with FortiPAM. In the Local Server Port field, enter the port for FortiClient to use to communicate with FortiPAM. The default port for this communication is 9191. If you change this value, ensure that you also change it in FortiPAM.

    Disable proxy (troubleshooting only)

    Disable proxy when troubleshooting FortiClient.

Advanced options

To configure advanced options:
  1. Go to Settings, and expand the Advanced section.
  2. Configure the following settings, and click OK:

    Default tab

    Select the default tab to display when opening FortiClient.

    Action for EMS invalid certificates

    Select the action to take when FortiClient attempts to connect to EMS with an invalid certificate:

    • Warn: warn the user about the invalid server certificate. Ask the user whether to proceed with connecting to EMS, or terminate the connection attempt. FortiClient remembers the user's decision for this EMS, but displays the warning prompt if FortiClient attempts to connect to another EMS (using a different EMS FQDN/IP address and certificate) with an invalid certificate.
    • Allow: allows FortiClient to connect to EMS with an invalid certificate.
    • Deny: block FortiClient from connecting to EMS with an invalid certificate.

    Enable Single Sign-On mobility agent

    Enable SSO.

    Enable Privilege Access Management

    Enable privilege access management (PAM). This enables FortiClient to communicate with FortiPAM. In the Local Server Port field, enter the port for FortiClient to use to communicate with FortiPAM. The default port for this communication is 9191. If you change this value, ensure that you also change it in FortiPAM.

    Disable proxy (troubleshooting only)

    Disable proxy when troubleshooting FortiClient.