Hi All
We are an msp who supply/support FortiGates to a number of clients. Only a few use licenced FortiClients with EMS and the benefits of support/Vulnerability scanning and the extra features that the full blown client provides.
For many others it’s the free/unsupported FortiClient VPN only client that’s in use. This is relatively easy to deploy/configure but becomes problematic when updates are required to plug security holes.
As any upgrade requires a removal/reboot/reinstall it’s pain when we’re talking about hundreds of endpoints. In addition, there are some recommendations (for sensible reasons) to use the native OS client that would dispense with these problems.
https://www.ncsc.gov.uk/collection/mobile-device-guidance/virtual-private-networks
Integrated vs third-party VPN clients
Most operating systems have a built-in VPN client available which can either be configured on the device or managed remotely. Integrated clients are normally free to use, work reliably, and are updated automatically, but can also be relatively limited in functionality. For example, there’s often no ability to configure routing rules, exceptions, or split tunnelling.
We recommend using the native client where possible, and our platform specific guidance provides configuration details. However, a range of commercially available third-party VPN clients exists.
Using a third-party VPN client increases the risk that operating system integration will be poor, and that consequently, some data may be sent outside the VPN. It also increases the number of software packages that need to be kept up to date, adding to the likelihood that some out-of-date software will be in use.
Has anyone switched from using the Forticlient VPN Only client to Windows 10 Native (IPSEC not SSL)?
Any issues/problems encountered by those who use the Windows native client?