Fortinet black logo

New Features

OS Zero Trust tagging rule supports comparators 7.2.2

OS Zero Trust tagging rule supports comparators 7.2.2

When creating an operating system (OS) Zero Trust tagging rule, you can select one of the following logical comparators:

  • = (Equal)
  • > (Greater than)
  • < (Less than)
  • >= (Greater than or equal to)
  • <= (Less than or equal to)

Prior to this improvement, when a new OS released, you had to manually update the rule to include the newly released OS version. Now, for example, if you configure a rule to apply to all OS versions greater than macOS Ventura, it would include any future macOS releases, and you would not have to manually update the rule each time Apple released a new macOS version.

You can use the comparators in combination with NOT.

FortiClient 7.2.2 and later versions support comparators. FortiClient 7.2.1 and earlier versions do not support comparators and apply rules with comparators as if they use =.

To tag a Fedora endpoint with a rule using operators:
  1. In EMS, go to Zero Trust Tags > Zero Trust Tagging Rules.
  2. Click Add, then Add Rule.

  3. For OS, select Linux.

  4. From the Rule Type dropdown list, select OS Version.

  5. Configure the following rules using comparators:

    • = Fedora Linux 36

    • NOT = Fedora Linux 35

    • < Fedora Linux 37

    • > Fedora 34

  6. Configure other fields as desired, then save.

    EMS tags an endpoint running Fedora Linux 36 with the tag configured for this rule.

OS Zero Trust tagging rule supports comparators 7.2.2

When creating an operating system (OS) Zero Trust tagging rule, you can select one of the following logical comparators:

  • = (Equal)
  • > (Greater than)
  • < (Less than)
  • >= (Greater than or equal to)
  • <= (Less than or equal to)

Prior to this improvement, when a new OS released, you had to manually update the rule to include the newly released OS version. Now, for example, if you configure a rule to apply to all OS versions greater than macOS Ventura, it would include any future macOS releases, and you would not have to manually update the rule each time Apple released a new macOS version.

You can use the comparators in combination with NOT.

FortiClient 7.2.2 and later versions support comparators. FortiClient 7.2.1 and earlier versions do not support comparators and apply rules with comparators as if they use =.

To tag a Fedora endpoint with a rule using operators:
  1. In EMS, go to Zero Trust Tags > Zero Trust Tagging Rules.
  2. Click Add, then Add Rule.

  3. For OS, select Linux.

  4. From the Rule Type dropdown list, select OS Version.

  5. Configure the following rules using comparators:

    • = Fedora Linux 36

    • NOT = Fedora Linux 35

    • < Fedora Linux 37

    • > Fedora 34

  6. Configure other fields as desired, then save.

    EMS tags an endpoint running Fedora Linux 36 with the tag configured for this rule.