| Description | This article describes how to fix an issue where FortiGate fails to obtain capability information from an Azure-Hosted FortiClient EMS. |
| Scope | FortiGate. |
| Solution |
Problem:
When trying to authorize Azure-Hosted FortiClient EMS from FortiGate, the following errors show in the GUI:
Run the following real-time debug commands on FortiGate:
diagnose debug reset diagnose debug application fcnacd -1 diagnose debug enable
The following errors will be shown in the CLI:
[ec_ez_worker_process:353] Processing call for obj-id: 0, entry: "api/v1/system/serial_number"
Solution:
When using FortiClient EMS server FQDN in Azure Cloud, check the DNS server in Azure to make sure it is capable of resolving the FortiClient EMS server FQDN. Additionally, FortiGate itself needs to be able to resolve the FortiClient EMS server FQDN that is hosted in Azure cloud.
As a workaround, the IP address of FortiClient EMS can be used and it should work as long as there is reachability between FortiGate and FortiClient EMS. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.