Description |
This article describes a scenario where FortiClient's telemetry got into a 'Not reachable' state as it failed to connect to the EMS cloud due to DNS being blocked by the application firewall. |
Scope | FortiClient. |
Solution |
There is a possibility of the FortiClient application firewall blocking DNS resolution from FortiClient to EMS cloud FQDN, forticlient-emsproxy.forticloud.com if the application firewall is enabled in the application firewall endpoint profile and if an EMS administrator has configured to block the entire Network.Service category.
When this situation happens, FortiClient's telemetry enters into 'Not reachable' state.
To verify if it is a DNS resolution issue, review FortiESNAC error logs and it will indicate that FortiClient failed to resolve server address 'fct-FCTUID-tokencode-8013.forticlient-emsproxy.forticloud.com' as below:
To resolve this issue, in Endpoint Profiles -> Application Firewall -> Edit the affected firewall profile -> Application Overrides, add DNS application signature and set Action to Allow in Application Overrides as shown below: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.