question

adriangonzalez avatar image
0 Likes"
adriangonzalez asked

CAN I BLOCK USERS THAT HAVE NOT THE LATEST UPDATE IN FORTICLIENT VPN?

I have been trying to reach all my users to update forticlient vpn, but it is not possible, as sometimes they do not even come to the office.

I was wondering if i could set some kind of blocking in Firewall if the user does not have forticlient beyond 7.0.1 version.

I know I could disable the user, but they must keep working and I have been told no to disable them. That is why this is the only thing that comes to my mind.


Thanks in advanced

FortiClient
10 |600

Up to 8 attachments (including images) can be used with a maximum of 1.0 MiB each and 10.0 MiB total.

1 Answer

·
fgdocs avatar image
0 Likes"
fgdocs answered

So natively, you can use host check to block a SSL VPN connection if FortiClient-AV or FortiClient-FW is not installed.

https://docs.fortinet.com/document/fortigate/7.2.4/administration-guide/32970/configuring-os-and-host-check

But it sounds like this is not your intention. There is currently no way to disable connection based on FCT version, unless you tag each endpoint using classification tags manually and then apply the ZTNA tags to firewall rules with IP MAC based access control.

https://docs.fortinet.com/document/fortigate/7.2.4/administration-guide/477578/ztna-ip-mac-based-access-control-example


However, you can consider using other ZTNA tags to block your endpoint from connecting using this method:

https://docs.fortinet.com/document/forticlient/7.0.7/ems-administration-guide/701440/configuring-a-profile-to-allow-or-block-endpoint-from-vpn-tunnel-connection-based-on-the-applied-zero-trust-tag


10 |600

Up to 8 attachments (including images) can be used with a maximum of 1.0 MiB each and 10.0 MiB total.

Write an Answer

Hint: Notify or tag a user in this post by typing @username.

Up to 10 attachments (including images) can be used with a maximum of 1.0 MiB each and 10.0 MiB total.

Welcome to FortiAnswers

FortiAnswers is the space dedicated to FortiSASE and FortiOS questions and suggestions.

  • Please review the Community guidelines
  • If you are a moderator, please refer to the Moderation guidelines
  • If something in the above guidelines is unclear, please post your question to the Community Feedback space or the Moderators' space