Skip to main content
adriellousada
Staff
Staff
August 18, 2026

Technical tip: Troubleshooting FortiClient EMS classification tag synchronization failures

  • August 18, 2026
  • 0 replies
  • 79 views

Description

This article describes how to troubleshoot a classification tag sync failure.

Scope

 FortiClient EMS.

Solution

In some cases, it may be necessary to use classification tags for endpoints in FortiClient EMS.

After creation, it can be verified that some of the TAGs were not shared with the FortiGate.

The main reasons for this could be:

  1. The Fabric connector configuration in FortiClient EMS does not have the classification tag sharing option configured:

    84bb2c56.png


    Therefore, review this configuration by navigating to Fabric & Connectors -> Fabric Devices to enable the Classification Tags tag type.

  2. The classification tag contains prohibited characters:

    5f4e2273.png


    Due to restrictions on the use of certain characters in FortiGate objects, an object will not be created on the FortiGate if, for example, a tag containing parentheses is created. This means the tag will not be synchronized to the FortiGate.

    If a classification tag contains disallowed characters, it will be necessary to delete and recreate the tag. Avoid using characters such as '<>()#"'', opting instead for '+', '-', or '_' to ensure the tag is shared successfully.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!