| Description | This article describes the 'ztna-ems-tag-negate' option, to allow or deny policies to match traffic when a specified EMS tag is not present on the endpoint. |
| Scope | FortiOS 7.6.1+. |
| Solution |
Firewall policies with EMS TAGs typically evaluate the TAGs synced from the EMS. The TAG including IP and MAC information can be viewed with the CLI command 'diagnose firewall dynamic list'. Once the TAG is available in FortiGate 'ztna-ems-tag-negate' can be enabled to deny the traffic along with the correspondent TAG.
The 'ztna-ems-tag-negate' option adds a logical 'NOT' condition to ZTNA EMS tag checks within the policies. When enabled, the proxy policy is evaluated as a match if the client does not have the configured EMS tag. This enables administrators to implement policies such as:
The option is automatically hidden when no EMS tag is configured, ensuring valid configuration and preventing unused settings.
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.