Creating a customized installer using FCRepackager
Blocking all connections that have no firewall rule
Changing the certificate key size
Creating the custom MSI installation file
12
3 Set the value of DontRateIP to 1.
By default, if there is no firewall rule for a particular network connection, the FortiClient
application asks the user whether to allow the connection. For an enterprise deployment,
you might prefer to block all connections except those that have a specific firewall rule to
permit them.
To block all connections by default
1 Using regedit or regedt32, edit the following key:
HKEY_LOCAL_MACHINE\Software\Fortinet\FortiClient\FA_FCM\firewallbehavior
2 Set the key value to 0.
The default VPN certificate key size in FortiClient v4.0 is 2048 bits. You can change the
size.
To change the certificate key size
1 Using regedit or regedt32, edit the following key:
HKEY_LOCAL_MACHINE\Software\Fortinet\FortiClient\FA_CERT\key_size
2 Set the key value to one of: 1 (1024 bits), 15 (1536 bits), 2 (2048 bits), 3 (3072 bits) or
4 (4096 bits).
With the sample application configured as you want for your users, you can create a
custom MSI installer file for your customized FortiClient application.
1 Determine the command line options you need for your customized FortiClient installer
from the following table.
Table 1: FCRepackager options
Specify license key (for standard fixed license or
volume license from FDS, not for enterprise license)
Lock down program for FortiManager.
Specify the plain text password.
Set random AV update time between specified hours.
The sample installation must contain an update
schedule.
Specify which features can be installed.
The resulting .msi file cannot be used for upgrades,
only for new installations.
If the -i option is not specified, all features are available
for installation.
Shrink the .msi file by removing files for unused
features. Valid only when used with -m option.
Refer to the FCRepackager_Readme.txt file for more information about command line
options.
-k <license_key>
-L <lockdown_password>
-s <start_hour>-<end_hour>
-i <feature1>[,<feature2>] ...
Features are:
AV
VPN
FW
WF
AS
AL
Note: feature names are case-sensitive.
-z
FortiClient Endpoint Security Version 4.0 MR1 Administration Guide
Custom Installer Packages
Antivirus
Virtual Private Network
Firewall
Web filter
Antispam
AntiLeak
04-40001-99556-20090626
http://docs.fortinet.com/
•
Feedback
Need help?
Do you have a question about the Version 4.0 MR1 and is the answer not in the manual?