FortiSASE
FortiSASE delivers both a consistent security posture and an optimal user experience for users working from anywhere. Secure your hybrid workforce by closing security gaps, plus simplify operations.
ihaidar
Staff
Staff
Article Id 335789
Description This article describes how to resolve the certificate error shown on FortiGate.
Scope FortiSASE, FortiGate.
Solution

The FortiGate is displayed as disconnected from FortiSASE and it shows the error below:

 

error.png


Error2.png

 

Test the connectivity between FortiGate and FortiSASE by executing the below command:

 

diag endpoint fctems test-connectivity 1
Connection test was successful.

diag test application fcnacd 2
2024-08-21 12:59:16 EMS context status:

 

Verify FortiClient EMS’s certificate by using the following command. The output will show the certificate details and will ask to trust the certificate as shown below:

 

exec fctems verify 1

 

EMS configuration needs user to confirm server certificate.
Do you wish to add the above certificate to trusted remote certificates? (y/n)y

Certificate successfully configured and verified.

 

To verify that it is connected to FortiSASE now, execute the below commands:

 

SILAL-PRM-FW01 # diag test application fcnacd 2
EMS context status:


FortiClient EMS number 1:
name(id): FortiSASE-Cloud(1) confirmed: yes
fetched-serial-number: <FCTEM_Serial Number>
fetched-tenant-id: 00000000000000000000000000000000
user-data:
verified capabilities: true
verified identity: true
interface-selection-method: 0
verify-peer-method: 4
Websocket status: connected, oif: 0