FortiClient Lockdown | You can lock the configuration of FortiClient agents. Users cannot remove the software and cannot change the settings. Users can connect and disconnect VPN tunnels and can change certificates and CRLs. You can override the lockdown setting on groups or individual FortiClient agents. See “Configuring system settings of a FortiClient agent”. | |
Default policy for new client | Select Enable Lockdown or Disable Lockdown. | |
Lockdown password | Enter a password. You can provide this password to users to enable them to modify their own configuration, using FortiClient override. For information on the FortiClient override feature, see FortiClient Endpoint Security User Guide. | |
Apply Lockdown Setting to All | Apply the lockdown settings to all FortiClient agents that this FortiManager unit manages. | |
Client Discovery | ||
Accept client request | Select the network interfaces (ports) on which the FortiManager unit listens for registration requests, either broadcast or unicast, from FortiClient computers. | |
When new client is discovered | Select Auto-populate managed client list if you want newly-discovered FortiClient agents added to the Managed Client and Ungrouped Client lists in the navigation pane. Otherwise, select Add to temporary client list. | |
Other Setting | ||
Do retrieve configuration from client | Select to retrieve the configuration from a new client when it is added to the managed clients list. | |
Don't search static group and its child group(s) | Enable only to speed up dynamic grouping where there are no static groups with dynamic child groups. The default is to not enable this option. | |
Keep monitor alerts duration | Enter the time that firewall and antivirus alerts are retained before automatic deletion. Enter 0 to keep alerts until you manually delete them. | |
Keep management Event Logging duration | Enter the number of days to retain management event logs. |