Skip to main content
kmak
Staff
Staff
July 8, 2026

Troubleshooting Tip: How to resolve FortiClient VPN connection failure issue with debug message 'EMS SN check failed' found in FortiGate

  • July 8, 2026
  • 0 replies
  • 132 views

Description

This article describes the steps to resolve the FortiClient VPN connection failure issue with the debug message 'EMS SN check failed' found in FortiGate.

Scope

FortiSASE-Sovereign.

Solution

Scenario:

  1. The FortiSASE-Sovereign has the tenant account with endpoint devices connecting to the tenant account. The endpoint device encountered an error when connecting to the IPsec VPN for the SIA/SPA tunnel.

454c56b1.jpg


f7fddba6.jpg

 

  1. Access the PoP FortiGate where the endpoint’s FortiClient is connecting, and run the command below to debug the IPsec VPN connection.

diagnose debug application ike -1
diagnose debug enable


4703b35c.jpg

 

  1. The error message 'EMS SN check failed' appears in the debug output.

7ab37b95.jpg

 

Resolution:

  1. To resolve the FortiClient IPsec VPN connection error due to the issue 'EMS SN check failed' in PoP FortiGate, disable the EMS SN check in the FortiSASE-Sovereign’s Tenant account settings. Log into the FortiSASE-Sovereign tenant portal and navigate to the Service Settings page. Toggle to disable the option 'Enable EMS SN Check'.

c44beeeb.jpg

 

  1. Upon a config change in the FortiSASE-Sovereign portal PoP settings, select the 'Install Config' option in the Configuration Task to apply the changes to the PoP FortiGate.

0a64d221.jpg

 

  1. Retry the IPsec VPN connection from the endpoint’s FortiClient, and the connection should be successful now.

d540ac04.jpg

 

  1. Create a Support ticket for FortiSASE-Sovereign service to further troubleshoot the IPSec VPN connection error if necessarily.

 

Related document:

Multi-Tenancy Onboarding