Description
Fortinet FortiClient VPN / ZTNA
Endpoint Agent for Visibility, Protection, and Secure Remote Access
FortiClient is a unified endpoint agent that delivers:
-
Secure remote access (SSL VPN, IPsec VPN, and Universal ZTNA)
-
Endpoint visibility and telemetry
-
Compliance enforcement
-
Endpoint protection (EPP / APT features)
-
Centralized management via EMS or Cloud
It integrates directly into the Fortinet Security Fabric, giving FortiGate, FortiAnalyzer, EMS, and other Fabric components a unified, real-time view of endpoint posture and activity.
Core Capabilities
1. Secure Remote Access (VPN + ZTNA)
SSL VPN and IPsec VPN
-
Supports SSL VPN with split tunneling
-
Supports IPsec VPN (IKE mode configuration)
-
Always-on VPN and autoconnect
-
Dynamic VPN gateway selection
-
Multifactor authentication (MFA support)
-
Prevents traffic backflow from internet to corporate network
Split tunneling reduces latency while maintaining secure segmentation.
Universal ZTNA (Zero Trust Network Access)
FortiClient establishes automatic, encrypted per-session tunnels to the FortiOS ZTNA Application Gateway.
Every session includes:
-
User verification
-
Device posture verification
-
Policy validation
-
Optional MFA
Access is granted per session — not per network — ensuring controlled, granular application access regardless of user location (on-prem or remote).
This replaces traditional "full network access" VPN models with application-level access control.
2. Security Fabric Integration
FortiClient integrates endpoints directly into:
-
FortiGate
-
FortiAnalyzer
-
FortiSandbox
-
FortiClient EMS
-
FortiClient Cloud
What This Enables
-
Real-time endpoint telemetry
-
Endpoint compliance enforcement
-
Vulnerability management
-
Dynamic access control
-
Automated quarantine of compromised endpoints
-
Unified reporting
FortiGate can use endpoint posture to dynamically allow or deny access.
Example:
A non-compliant device (outdated AV or missing patch) can automatically be restricted or quarantined.
3. Endpoint Protection (EPP / APT)
FortiClient includes next-generation endpoint security capabilities:
AI-Powered NGAV
-
Detects known and unknown malware
-
Cloud-based threat intelligence via FortiGuard
Exploit Prevention
Prevents vulnerability exploitation before malware executes.
Ransomware Protection
-
Detects ransomware behavior
-
Can roll back malicious changes
-
Restores endpoints to pre-infection state (Windows supported)
Removable Media Control
Prevents unauthorized USB and external device use.
Application Firewall
Controls application behavior and traffic at the endpoint level.
FortiSandbox Integration
Suspicious files are analyzed:
-
On-prem sandbox
-
SaaS sandbox
-
PaaS sandbox
-
FortiClient Cloud Sandbox
Detailed process tree and behavior analysis available in EMS.
4. Web Filtering & SaaS Control
FortiClient enforces web security even when users are remote.
Includes:
-
Web content filtering
-
Keyword-based filtering
-
YouTube channel filtering
-
SaaS control
-
Botnet protection
A FortiClient license also enables:
-
Inline CASB (via FortiGate)
-
API-based CASB (FortiCASB license included)
This extends security policies beyond the corporate perimeter.
5. Endpoint Hygiene & Vulnerability Management
FortiClient reduces attack surface through:
-
Vulnerability scanning
-
Endpoint audit and remediation
-
Optional autopatching
-
Software inventory management
-
Detection of outdated or vulnerable applications
Real-time vulnerability dashboards allow IT teams to identify high-risk endpoints.
Central Management
FortiClient can be managed through:
-
FortiClient EMS (on-premise)
-
FortiClient Cloud (SaaS-based)
Central Management Features
-
Remote deployment of agents
-
Remote upgrades
-
Real-time dashboards
-
Active Directory integration
-
Dynamic group assignment
-
Posture-based virtual groups
-
Central quarantine management
-
Remote triggers
-
Automatic email alerts
-
Custom groups
-
Policy enforcement
Supports management of:
-
Windows
-
macOS
-
Linux
-
iOS
-
Android
-
Chrome OS
Platform Support
Supported Operating Systems
Windows
-
Windows 7 — 11
-
Windows Server 2012+
macOS
-
macOS 10.14+
Mobile
-
iOS 9+
-
Android 5+
Linux
-
Ubuntu 16.04+
-
Red Hat 7.4+
-
CentOS 7.4+
Chromebook Support Available
View data sheet: FortiClient Data Sheet

