Created on
03-13-2024
10:32 PM
Edited on
09-02-2024
10:49 PM
By
rvillaroman
Description | This article describes how to fix the EMS error (-1@_get_capabilities:471). |
Scope | FortiGate v7.0.x. |
Solution |
When an EMS server is added to the FortiGate settings, the EMS needs to authorize the FortiGate before they can communicate properly.
Checking the FortiGate settings for EMS via CLI:
config endpoint-control fctems end
From the CLI, FortiGate cannot communicate with EMS server:
LAB-FGT (root) # execute ping 10.68.243.30 --- 10.68.243.30 ping statistics --- LAB-FGT (root) #
Once the communication between EMS and FortiGate is restored, it is necessary to accept the certificate again.
When the FortiClient EMS is in the multi-tenancy mode, the configured IP/Domain name under the Fabric Connector in the FortiGate needs to be the FQDN address instead of the IP. The format of the FQDN address needs to be the 'tenancy name' + 'EMS FQDN'. For example, to connect to the tenant site 'default' on the EMS FQDN 'somedomain.it', the FQDN to be configured on FortiGate needs to be 'default.somedomain.it' and FortiGate should also be able to resolve it.
To verify the connectivity, FortiGate needs to ping the FQDN 'default.somedomain.it' instead of the EMS FQDN 'somedomain.it' only. If the 'somedomain.it' is configured as an IP/Domain name by mistake, FortiGate will get this error as well.
Related article: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.