Installing FortiClient for VPN Services (EMS)

Case Western Reserve University provides remote users with secure access to the network over the VPN client. VPN is a point-to-point connection between a personal computer and CWRU servers. Users must first download the VPN client for their respective operating system. Once they are connected through VPN, users can utilize a web browser to access various tools within CWRU such as the Software Center. Only active members of the university have the ability to utilize VPN. Alumni do not have access to this service.

This article documents the installation procedure for installing FortiClient and registering it to the FortiClient Endpoint Management Server (EMS) for proper licensing.

 

Installing FortiClient for macOS

Installing FortiClient for iOS or Android devices

 


Installing FortiClient for macOS

1)  Please uninstall any FortiClient VPN app (use "Uninstall Forticlient" app in Applications Folder )

2)  Download Fortclient Installer here.

3)  Open Forticlient install .dmg disk image

4)  Run "Install" pkg file using default options.

5)  Select "Allow" when ask " "FortiTray" would like to Add VPN Configurations."

6)  Allow Forticlient to make change to "Certificate Settings"

7)  After installation is completed, open "System Preferences" -> "Privacy & Security"

8)  Under "Security" section, look for a pending notification "System software from application "FortiClientNetwork" was blocked from loading.  Select the "Allow" button.
     ( If you may see a dialog box "System extension blocked", click the "Open Settings" button.)

9)  Open FortiClient app

10)  Enter EMS server address "fgt-ems-vpn1.case.edu" and register with the EMS server

Uploaded Image (Thumbnail)

11)  Verify FortiClient is now connected to EMS

Uploaded Image (Thumbnail)

12)  Establish VPN connection

Uploaded Image (Thumbnail)

13)  Disconnect VPN connection

Uploaded Image (Thumbnail)

 

 


Installing FortiClient for iOS or Android devices

1)  Please remove any existing FortiClient app (e.g. "FortiClient VPN" or FortiClient 6.0 (Legacy) )

Uploaded Image (Thumbnail)

Uploaded Image (Thumbnail)

2)  Open App Store, and search for "FortiClient"
3)  Install FortiClient app under Business Category (note the Icon is different.)

IOS

Uploaded Image (Thumbnail)

Android

Uploaded Image (Thumbnail)

4) Open the newly installed "FortiClient" app
5)  Grant permission for FortiClient if asked (e.g. notification, location access or camera)
6)  Review "Policy Highlights" and tab "I accept" button.

Uploaded Image (Thumbnail)
7)  Under "Please Login" screen, tab "User Input"

Uploaded Image (Thumbnail)

8)  Enter your name in the Name field and tab "Done" and tab "Next"

Uploaded Image (Thumbnail)

9)  If asked, tab "Allow" and allow "FortiClient"  to add new VPN Configuration

Uploaded Image (Thumbnail)
10) Enter device passcoded if needed

Uploaded Image (Thumbnail)
11)  Under "Zero Trust Telemetry" screen,   verify "Connect to" field is set to EMS IP.
12)  Tab "Specify IP" or "Specify EMS IP"

Uploaded Image (Thumbnail)

13)  Enter the follow information and tab "Done".  (Host =  fgt-ems-vpn1.case.edu and port  = 8013 ).

Uploaded Image (Thumbnail)

14) Tab allow if asked about "Untrusted Certification"

Uploaded Image (Thumbnail)
15)  Ensure "Zero Trust Telemetry Connection" is toggled ON.

Note:  If EMS connection is successful, you will see the "Centrally Managed by EMS" message.  You may have to force quit the FortiClient app and re-open.

Uploaded Image (Thumbnail)

Uploaded Image (Thumbnail)
16)  Tab "VPN" at the bottom of the screen

Uploaded Image (Thumbnail)
17) Tab "Connections"

Uploaded Image (Thumbnail)
18)  Tab "CWRU VPN" under Corporate VPN Gateway

Uploaded Image (Thumbnail)
19)  Verify 'CWRU VPN' connection is checked.

Uploaded Image (Thumbnail)

20)  Tab "<VPN" on top left to return to main VPN screen

Uploaded Image (Thumbnail)

 

Starting and disconnecting a VPN connection

1) Open "FortiClient" App
2)  Tab "Vpn" at the bottom of the screen to bring up VPN main screen

Uploaded Image (Thumbnail)
3)  Turn the "VPN" toggle to ON to start a VPN connection

Uploaded Image (Thumbnail)
4)  Enter your CWRU network ID and your passphase.  Be sure to respond to your DUO 2FA Prompt

Uploaded Image (Thumbnail)
5)  Note the status becomes "Connected" if authentication is successful.

Uploaded Image (Thumbnail)

6)  To disconnect, toggle "VPN" to OFF position.

 

Manually configure a VPN Profile (optional)

1)  Tab "VPN" at the bottom of the screen

Uploaded Image (Thumbnail)
2) Tab "Connections"

Uploaded Image (Thumbnail)
3)  Tab "Add Configuration.."

Uploaded Image (Thumbnail)
4) Enter the following information and tab "Save"
Name:  CWRU VPN
Host:  vpn2.case.edu
Port: 443
User:  abc123 (optionally, enter your CWRU network ID)

5)  Tab "<VPN" on top left and again on the next screen to return to main VPN screen

 

Uploaded Image (Thumbnail)

Details

Article ID: 17307
Created
Wed 11/15/23 4:18 PM
Modified
Fri 2/9/24 2:42 PM