Advanced Scenarios Custom Installer Packages
FortiClient Endpoint Security Version 4.0 MR1 Administration Guide
20 04-40001-99556-20090626
http://docs.fortinet.com/ • Feedback
Changing the default firewall action
By default, the FortiClient firewall allows unknown applications to access the network, or
asks the user, depending on the selected firewall profile. (An unknown application is one
that is not on the firewall applications list.) To make the FortiClient firewall always block
unknown applications, add the DEFAULTAPPLICATION=1 command line option when you
run the FortiClient installer.
Advanced Scenarios
Installing FortiClient as part of a cloned disk image
If you configure computer using a cloned hard disk image, you need to remove the unique
identifier from the FortiClient application. You will encounter problems with FortiManager
Server if you deploy multiple FortiClient applications with the same identifier.
This section describes how to include a custom FortiClient installation in a cloned hard
disk image but remove its unique identifier. On each computer configured with the cloned
hard disk image, the FortiClient application will generate its own unique identifier the first
time the computer is started.
To include a FortiClient installation in a hard disk image
1 Using an MSI FortiClient installer, install and configure the FortiClient application to suit
your requirements.
You can use a standard or a customized installation package.
2 Right-click the FortiClient icon in the system tray and select Shutdown FortiClient.
3 From the folder where you expanded the FortiClient .zip package, run
RemoveFCTID.exe. The RemoveFCTID tool requires administrative rights.
4 Shut down the computer.
5 Create the hard disk image and deploy it as needed.
Installing FortiClient on cloned computers
If you intend to make an image of the hard drive for deployment to other computers, you
need to shut down FortiClient and use the RemoveFCTID tool to remove the FortiClient
identifier. For more information, see “Installing FortiClient as part of a cloned disk image”
on page 20.
Installing FortiClient on Citrix servers
You can install FortiClient Endpoint Security on Citrix Presentation Server 4.5 in a
Windows Server 2003 or Windows Server 2008 Beta 3 environment.
You can use a standard or a customized installation package, but you must select the
Custom installation option and make sure that you do not install the VPN feature. Citrix
uses the Windows IPsec service, which the FortiClient VPN would disable.
Note: Do not make the RemoveFCTID tool part of a logon script.
Note: Do not reboot the Windows operating system on the computer before you create the
hard disk image. The FortiClient identifier is created before you log on.