| Description |
This article describes that ZTNA policy does not match after configuring the ZTNA firewall or proxy policy with ZTNA Tags:
diagnose wad dev query-by uid <uid> <EMS Serial number> 00000000000000000000000000000000 <----- The output may take 20 seconds to be displayed with only the text 'Response termination due to no more data'. |
| Scope | FortiGate v7.0 and above. |
| Solution |
For example: if the process ID for fcnacd is 172 and that for wad is 186 (found from diag sys top command), the following commands can be run to restart both processes:
diagnose sys kill <signal> <process ID> diagnose sys kill 11 172 diagnose sys kill 11 186
If the endpoint is not listed in 'matched endpoints', check if 'set pull-sysinfo' is enabled under 'config endpoint-control fctems' (it must be enabled):
config endpoint-control fctems edit <EMS_Entry> set pull-sysinfo enable (Enabled by default.) next end
If the endpoint is not listed in 'resolved addresses', it can be resolved by applying a change on the EMS server: Technical Tip: How to check the resolved addresses of ZTNA Tags in FortiGate. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.