Description | This article describes how to troubleshoot when some ZTNA Clients are denied by FortiGate with the message 'ZTNA tag verification failed – access denied'. |
Scope | FortiGate, FortiClient, and FortiClient EMS. |
Solution |
Certain Internal Resources access can be restricted only to the Endpoints configured with FortiClients using ZTNA Edition. However, some clients would be blocked by FortiGate with the message 'ZTNA tag verification failed – access denied'
The following configuration helps in fixing this issue,
config vpn ssl web host-check-software edit "FCT-ZTNA"
Ensure that the process 'FortiESNAC.exe' is running on those End Points being blocked. |
Labels: