Skip to main content
Contributor III
February 23, 2023

Technical Tip: FortiClient ZTNA access denied to certain PCs due to 'End-point SN miss matched'

  • February 23, 2023
  • 0 replies
  • 6494 views
Description

This article describes why some FortiClient users may see the following error when attempting to access a resource protected by FortiGate ZTNA:

 

Policy restriction! No policy matched! End-point SN miss matched. SN: 41D09397CECDAAF6CBB523F18508CF82xxxxxxxx ID: 45311937327F4C6B8A542432xxxxxxxx Timestamp: 1677028182

Scope

Windows FortiClient, ZTNA

Solution

This issue occurs when EMS attempts to update/modify the X.509 certificate issued to a FortiClient endpoint, but Windows is unable to successfully update the local copy. This issue can also occur if the user selected the wrong certificate or missed the browser verification prompt that is shown when accessing a ZTNA resource.

 

This article details two fixes. In cases where the user did not select the certificate or missed the browser verification prompt, try Method 1 for a faster fix:

 

Method 1:

  1. Close the web browser tab (or tabs) that display the ZTNA error.
  2. Clear the browser's cache.
  3. Relaunch the browser or re-open a tab to access the ZTNA resource again. Make sure the correct FortiClient EMS certificate is chosen when prompted for verification.

 

If access is still denied, attempt Method 2:

 

Method 2:

  1. Disconnect FortiClient from EMS by opening the Zero Trust Telemetry page and selecting the Disconnect button.

 

Muhammad_Haiqal_0-1677132509010.png

 

  1. With FortiClient now disconnected from EMS, locate the FortiClient icon in the Windows taskbar (typically bottom-right of desktop), then 'right-click' and select Shutdown FortiClient:
                                                                     
Muhammad_Haiqal_2-1677132576841.png

 

  1. Open a Command Prompt ('cmd') as an Administrator, then type net stop fortishield and hit Enter. This stops the currently-running FortiClient process.

 

Muhammad_Haiqal_3-1677132608075.png

 

  1. Open File Explorer and navigate to C:\ProgramFiles\Fortinet\FortiClient\cert\local, then delete all files in this folder. EMS will replace these local certificates once rejoined.

 

Muhammad_Haiqal_1-1677132525877.png

 

  1. Restart/reboot the Windows PC.
  2. Re-open FortiClient and reconnect to EMS again. This can be done by entering the IP/FQDN of the EMS server into FortiClient, or by using an EMS-based Invitation Code. See also:


If the issue persists, contact Fortinet technical support for further assistance: FortiCare Support.

 

Related article:

Technical Tip : Unable to Shutdown FortiClient when connected EMS

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.