I am using FortiClient Version 7.2.7 and whenever clients try to connect to the EMS withing the LAN they receive a "failed to verity server certificate" message.
Connecting via a mobile hotspot works.
Does anyone know why this is happening and how i can fix it?
Are you connecting with hostname or IP address?
Bear in mind that if the used hostname or IP is not the same as the certificate subject or SAN then you will receive certificate error.
I am connecting to the host name
The name is the same as in the certificate
This should mean that you don't see the same certificate on WAN (mobile hotspot) and on LAN, which is not supposed to be so.
Try run this command from both WAN and LAN to confirm that the certificate is (or is not) the same.
openssl s_client -connect YourServerIP:8013
Starting from FortiClient 7.2.5+, renewing the SSL cert on FortiGate will trigger a security feature on FortiClient. This is known and will change in the next version. You can contact TAC for the issue id.
Solution is to disconnect FCT from EMS and shutdown FCT (right click tray area and shutdown). Then delete FortiClient folder in %appdata% and %localappdata% and reboot the system.
User | Count |
---|---|
2571 | |
1364 | |
796 | |
651 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.