Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
NeilG
Contributor

Forticlient 5.4.5 on Windows 10 1709 does not correctly register with Windows Security Cen

Problem: Forticlient 5.4.5 on Windows 10 1709 does not correctly register with Windows Security Center - it reports that it is the active primary AV when it is NOT (when forticlient real time scanning is disabled)

 

FortiClient: 5.4.5.0891

[ul]
  • Realtime Protection: Disabled[ul]
  • File-based malware scanning                          OFF
  • Extended scanning using FortiSandbox            OFF
  • Block malicious website                                  OFF
  • Block know attack communications channels    OFF[/ul][/ul]

     

    Fortigate: v5.4.8,build1183

       (See Image of the FortiClient profile)

     

     

     

    Reproduction Steps:

    Boot Windows computer

    Sign in with account that has local admin rights

    confirm windows Defender is active and primary

    Install forticlient from MSI

    As soon as Fortclient shortcut shows up on the desktop, right click and Run-As Admin level

    Drill into Antivirus -> Realtime Protection -> click "sprocket"

    Uncheck the "Use the web filter exclusion list"

    Uncheck all the boxes

    Set scheduled scan for 1st of Month at 14:00 hrs

    Click OK

    Now click on Compliance 

    Enter Fortigate IP and register

     

    At some point while in the dialog the  forticlient had started downloading components

    When the Fortigate IP is registered it pulls down the config as shown in the attached image.

     

    At this point the FortiClient is NOT the primary AV - but if you Open Windows Defender Security center you will a message under the "Virus and threat protection" section:

    "Status unavailable, open ForitClient Antivirus for Information"

     

    Reboot

    Defender is still disabled

     

    Uninstall FortiClient and Reboot

     

    Once uninstalled, Defender turns back on.

     

    ----

    Note: In this configuration the Forticlient is supposed to be just enforcing patches/updates + making sure the built in Windows Defender is active and then running a monthly scan.

     

    To me this seems like a bug with FortiClient not properly re-enabling Windows defender as Realtime scanner when FortiClient AV realtime is disabled.

  • 1 REPLY 1
    arlem
    New Contributor II

    I have more or less the same issue with version 6.0.6 but with Kaspersky as the AntiVirus. 6.0.5 does work fine.

     

    https://forum.fortinet.com/tm.aspx?tree=true&m=174790&mpage=1

     

    Labels
    Top Kudoed Authors