Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
migacz
New Contributor III

FortiClient Endpoint Unprotected status

Hi 

i just upgrade EMS server to 1.2.4 and now i have Unprotected status on all my endpoints, any idea why?

Clients are connected to EMS server, up-to-date, telemetry is OK

M

 

1 Solution
Carl_Wallmark

Is that not old computers in your AD ? Computers that is not deleted or does not have forticlient installed? The EMS scans all of the directory.

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

View solution in original post

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
6 REPLIES 6
wizenhimur
New Contributor

I just upgraded to 1.2.4 and having same issue any fix?

Carl_Wallmark

Is that not old computers in your AD ? Computers that is not deleted or does not have forticlient installed? The EMS scans all of the directory.

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
migacz
New Contributor III

no fix, i thing it is some bug

migacz
New Contributor III

i dont have old computers accounts, only active

 

mphillips

Has there been any real resolution to this? I am having the same issue. It says I have "144 unprotected." I am 100% sure these aren't all old computers, since this is basically a total of all computers in my organization- and almost all do have Forticlient installed. They also have real time antivirus protection enabled, application & web firewall enabled, and are sending telemetry to Fortigates.

mphillips

Ok- by toggling around with filters I think I have it figured out. Seems to be that "unprotected clients" are clients that are not participating in compliancy. So if you are not using compliancy through Forti's security Fabric, all active computers will show up as "unprotected."

 

Here's how I determined it with the filters. My organization has a combination of active and inactive computers (222 endpoints to be exact). My "unprotected clients" total is 144. When I selected the "not participating in compliancy" filter, I got a total of 143 endpoints, which I figured is close enough.

Labels
Top Kudoed Authors