FortiClient
One endpoint agent, ZTNA, VPN, posture and endpoint protection
- Licensing
- Per endpoint, ZTNA, EPP/APT and SASE tiers priced separately
- Full support
- Windows, macOS
- Partial support
- Linux, Chromebook
FortiClient is the endpoint's connection to the Security Fabric: ZTNA and VPN access, device posture reporting, vulnerability scanning and endpoint protection in a single agent. Windows and macOS carry the full feature set; Linux and Chromebook support is partial, and mobile platforms carry ZTNA, Fabric components and VPN but not the EPP/APT options.
Where it fits, and where it stops fitting
Check the platform matrix against your actual fleet before licensing, a Linux-heavy or Chromebook-heavy estate gets partial coverage, and that needs to be known before rollout rather than discovered during it. The licence tiers differ substantially: buying the cheapest and finding it lacks endpoint protection is a common and avoidable mistake.
Highlights
- ZTNA, VPN, posture and EPP in one agent
- Full feature set on Windows and macOS
- Reports device posture to FortiGate for conditional access
- Submits unknown files to FortiSandbox
Typical deployments
- Migrating from network-level VPN to per-application ZTNA
- Enforcing device posture before granting network access
- Consolidating four endpoint agents into one
What to work out first
FortiClient is the endpoint's connection to the Security Fabric: VPN and ZTNA access, device posture reporting, vulnerability scanning and endpoint protection, in a single agent with a single deployment story.
Platform coverage is not uniform and this matters when planning. Windows and macOS carry the full feature set, ZTNA, next-generation endpoint security, cloud-based SASE options, Fabric components and VPN. Linux and Chromebook support is partial, and Android and iOS carry ZTNA, Fabric components and VPN but not the EPP/APT options.
Questions worth answering before you order
What is your device mix?
Check the platform matrix against your actual fleet before licensing. A Linux-heavy or Chromebook-heavy estate gets partial coverage, and that needs to be known up front rather than discovered at rollout.
ZTNA or VPN?
ZTNA is per-application and removes the network-level lateral movement a VPN permits. New deployments should generally start there; FortiClient does both during migration.
Which licence tier?
The tiers differ substantially in what they include, ZTNA, EPP/APT, and cloud SASE options are separate. Buying the cheapest tier and discovering it lacks endpoint protection is a common and avoidable mistake.
What this includes
Fortinet publishes no throughput table for this product; it is licensed per user, endpoint, workload or account. What follows is capability and sizing, not benchmarks.
What you are buying
| Licensing | Per endpoint, ZTNA, EPP/APT and SASE tiers priced separately |
|---|---|
| Full support | Windows, macOS |
| Partial support | Linux, Chromebook |
| Mobile | Android and iOS, ZTNA, Fabric components and VPN only |
How this is sized
Fortinet licenses this product per user, endpoint, workload or account rather than by appliance throughput, so there is no comparable performance table to publish. We size it from your actual environment, tell us the numbers and we will work it through with you.
| Licensing | Per endpoint, ZTNA, EPP/APT and SASE tiers priced separately |
|---|
Sources
- Fortinet product line overview, retrieved 2026-09-01
Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order; we will.