FortiGate SSL-VPN: Do I have to use EMS?

Hi,

I’ve been away from Fortinet for a couple of years and now have to set up client VPN on some FortiGate machines. I stumbled across this sentence in the Getting Started section of the documentation:

“In 7.0.7, you must use FortiClient with EMS”

I don’t need any of the features EMS provides. I just want plain-old-vanilla SSL VPN. In the old days, I would simply roll out the FortiClient (licensed on the FortiGate) and be done with it.

Is this no longer available? I have to install an EMS server?

Kind of confused… if someone could send me on the right track, I’d greatly appreciate it. Thank you!

“plain-old vanilla” SSL-VPN is still perfectly functional with the free FortiClient variant. :slight_smile:

The full Forticlient need EMS for licensing.

What you want is Forticlient VPN only.

Just make sur you download the VPN only client and you’ll be good.

Thank you guys, that sounds really good. I am going for the VPN-only variant :slight_smile:

Look for FortiClient VPN. That is what you’re after.

FortiClient EMS is a really nice solution. We used the VPN only version for half our workforce last year and now are deploying EMS company wide. You get a lot more out of it. Pricing was very reasonable at around $5k for 500 machines.

If we pay for the client, does it have auto update? Trying to update the client in mass is challenging

That’s one of the many features in the base EMS. You set from the EMS server “thou must run v7.x.x” and it’ll deploy a new package on next update from client (every 3 minutes I think it is… there’s a timer, and it’s short!).

It won’t auto update you without the admin making the change at the profile on the server.