I have succesfully connected EMS and FGT. I can see tags (populated with correct IPs), everything seems fine. BUT, when configuring the IPv4 policy with the ZTNA tag, traffic will not match this policy even though the resolved IP is correct. Traffic keeps matching the implicit deny policy.
Has anyone got away with this? Seems like a bug, I have a remote session scheduled but still would like to know if someone has this scenario working.
FGT is in 7.0.5, FC is 7.0.5 and FC EMS is in 7.0.4 (latest versions).