Technical Tip: FortiClient ZTNA access denied to certain PCs due to 'End-point SN miss matched'
| Description | This article describes why some FortiClient users may see the following error when attempting to access a resource protected by FortiGate ZTNA:
Policy restriction! No policy matched! End-point SN miss matched. SN: 41D09397CECDAAF6CBB523F18508CF82xxxxxxxx ID: 45311937327F4C6B8A542432xxxxxxxx Timestamp: 1677028182 |
| Scope | Windows FortiClient, ZTNA |
| Solution | This issue occurs when EMS attempts to update/modify the X.509 certificate issued to a FortiClient endpoint, but Windows is unable to successfully update the local copy. This issue can also occur if the user selected the wrong certificate or missed the browser verification prompt that is shown when accessing a ZTNA resource.
This article details two fixes. In cases where the user did not select the certificate or missed the browser verification prompt, try Method 1 for a faster fix:
Method 1:
If access is still denied, attempt Method 2:
Method 2:
Related article: Technical Tip : Unable to Shutdown FortiClient when connected EMS |




