Install FortiClient VPN
Last updated
Was this helpful?
Last updated
Was this helpful?
The following instructions guide you though the manual installation of FortiClient on a macOS computer. For more information, see the FortiClient (macOS) Release Notes.
After manually running the FortiClient installer on a macOS computer, you must enable certain permissions and perform other actions for FortiClient to work properly. This topic provides instructions on the necessary configurations. The process is as follows:
Install FortiClient on a macOS computer using the installer file. See To install FortiClient on a macOS computer:.
Activate system extensions. See To activate system extensions:.
(macOS 11 Big Sur and 10.15 Catalina only) Enable full disk access. See To enable full disk access:.
Enable notifications. See To enable notifications:.
Depending on what features are enabled on EMS, installing FortiClient (macOS) may require admin credentials to handle prompts for system keychain changes and granting permissions under Security & Privacy.
For FortiClient upgrade, system certificates and security permissions remain unchanged, so no special user privileges are required.
Double-click the FortiClient_7.4.2.xx_macosx .dmg installer file. The FortiClient for macOS dialog displays.
Double-click Install. The Welcome to the FortiClient Installer dialog displays.
(Optional) Click the lock icon in the upper-right corner to view certificate details and click OK to close the dialog. Click Continue.
Read the Software License Agreement and click Continue. You have the option to print or save the Software Agreement in this window. You are prompted to Agree with the terms of the license agreement.
If you agree with the terms of the license agreement, click Agree to continue the installation.
Depending on your system, you may be prompted to enter your system password.
After the installation completes successfully, Click Close to exit the installer. FortiClient has been saved to the Applications folder.
If using macOS Mojave (version 10.14), you must reboot the macOS device after installing FortiClient (macOS). FortiClient (macOS) displays the following prompt after installation. Click Restart System:
Double-click the FortiClient icon to launch the application. The application loads to your desktop.
After you perform an initial install of FortiClient, the device prompts you to allow some settings for FortiClient processes. You must have administrator credentials for the macOS machine to configure these changes.
You must allow the macOS system software to load the FortiTray.
To allow FortiTray to load:
Do one of the following:
If using macOS Sequoia (version 15), go to Settings > General > Login Items & Extensions > Network Extensions.
If using another macOS version, go to Settings > Privacy & Security.
Enable FortiTray.
You must enable the FortiClientProxy extension for Web Filter to work properly. You must enable the FortiClientPacketFilter extension for Application Firewall and network lockdown to work properly. The FortiClient (macOS) team ID is AH4XFXJ7DK.
To enable the FortiClientNetwork extension:
Do one of the following:
If using macOS Sequoia (version 15), go to Settings > General > Login Items & Extensions > Network Extensions.
If using another macOS version, go to Settings > Privacy & Security.
Enable the FortiClientProxy and FortiClientPacketFilter toggles.
Verify the extension status by running systemextensionsctl list
in the macOS terminal. In the output, the FortiClientPacketFilter extension displays as macos.webfilter. The following provides example output when the extension is enabled:
The com.fortinet.forticlient.macos.proxy system extension works as a proxy server to proxy a TCP connection. macOS manages the extension's connection status and other statistics. This resolves the issue that Web Filter fails to work when SSL and IPsec VPN are connected.
FortiClient (macOS) automatically installs the extension on an M1 Pro or newer macOS device.
macOS 11 Big Sur and 10.15 Catalina include security setting changes, which require you to enable full disk access for FortiClient services. If you do not grant full disk access to FortiClient services, FortiClient only provide partial protection of files in the /Applications directory. The first time that FortiClient detects an attempt to run an executable file located in another protected location on the endpoint as malware protection, macOS denies FortiClient access and prompts the user to grant full disk access.
Go to System Preferences > Security & Privacy tab, and select Full Disk Access
To make changes, click lock icon on the bottom left, enter your credentials, and Unlock.
Select the following services to grant them full disk access:
fctservctl2
FortiClient
If you did not grant full disk access permissions for the daemons, you can check their status on the Settings tab under Privacy Status. Click Open File Access to grant permissions for the daemons. If you do not configure this, macOS displays a popup asking for permissions each time that you use a feature related to one of the daemons, such as scanning for viruses.
After initial installation, macOS prompts the user to enable FortiClient (macOS) notifications.
Go to System Preferences > Notifications > FortiClientAgent.
Toggle Allow Notifications on.