Skip to main content
kgeorge
Staff
Staff
February 24, 2025

Technical Tip: Some ZTNA Clients are blocked by FortiGate with Error 'ZTNA tag verification failed – access denied'

  • February 24, 2025
  • 0 replies
  • 813 views
Description This article describes how to troubleshoot when some ZTNA Clients are denied by FortiGate with the message 'ZTNA tag verification failed – access denied'.
Scope FortiGate, FortiClient, and FortiClient EMS.
Solution

Certain Internal Resources access can be restricted only to the Endpoints configured with FortiClients using ZTNA Edition.

However, some clients would be blocked by FortiGate with the message 'ZTNA tag verification failed – access denied'

 

The following configuration helps in fixing this issue,

 

config vpn ssl web host-check-software

    edit "FCT-ZTNA"
        config check-item-list
            edit 1
                set target "FortiESNAC.exe"
                set type process
            next
         end
     next
end

 

Ensure that the process 'FortiESNAC.exe' is running on those End Points being blocked. 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!