Technical Tip: Correct procedure to create FortiClient EMS connector when FortiGates are in Security Fabric
| Description | This article explains why certain FortiGates in the same Security Fabric show 'EMS certificate not authorized', despite already being authorized in EMS -> Administration -> Fabric Devices. |
| Scope | FortiClient EMS versions are 7.0.x and 7.2.x. |
| Solution | It is important to understand that when FortiGates are in the Security Fabric, all FortiGates must be in the Fabric first, before creating the EMS Connector in the root FortiGate. Meaning:
In the case where root FortiGate is authorized with EMS, but downstream FortiGates fails to authorize the EMS certificates, follow the below verification steps:
The different naming in the certificate causes downstream FortiGate to be unable to verify the EMS certificate.
The solution is to delete the existing 'CA_Cert_1' in downstream FortiGate so that it can import the correct 'csf_CA_Cert_1' from the root FortiGate again. Follow the below steps:
|



