Hi,
I have FortiClient EMS, FortiManager, and several FortiGates in my environment.
EMS is connected to each FortiGate and showing "connected" in the Fabric Connectors;
In FortiManager, I have a Global Header Policy applied to all FortiGates;
This policy has an EMS classification tag as part of the source match condition.
Problem is devices without the EMS tag are still matching the policy.
Only troubleshoot I was able to do is running <diag user device list> only to find that there are no tags showing up.
Forticlient EMS v7.4.3
Fortimanager v7.4.6
Fortigate(s) v7.4.7
I would appreciate some help on how to further troubleshoot the issue.
Thanks in advance.
Hi Joao
When you open the policy from FortiGate WebUI (not FMG) do you see the tags are set up properly?
Hi, actually I can't see the tags anywhere inside the policy.
Thanks.
If you can't see it then you may need to enable Zero Trust Network Access in feature visibility.
Thanks for your reply.
Just to make sure we are on the same page, the tags I am trying to enable are ForticlientEMS Classification Tags (like the ones in the image below), and not the Security Posture Tags
Other issue is I am not able to enable the feature Zero Trust Network Access, as the instructions says that it must be enabled via CLI with two commands, however I dont have the set proxy-and-explicit-proxy enable under config system global.
As I said in the first post, this is a firewall header policy created on Fortimanager and pushed to the fortigates, and the tag is correctly presented on the Fortimanager side, my doubt now is if it should be presented in the individual firewalls policy as well.
Thanks again for your support.
Created on 09-09-2025 02:10 AM Edited on 09-09-2025 02:12 AM
hi,
in EMS you would need to ensure that in Fabric&Connectors > Fabric Devices > you have in Tag Types Being Shared , Classification Tags enabled to send to the FortiGates ( in Policy&Objects > ZTNA > Security Posture Tags you should see the CLASS IP tags [ Category: Classification ] from EMS ) and under the FortiGate > Fabric Connectors > EMS , CLI configuration you have pull-tags enabled ( which should be enabled by default if you didnt changed it )
Created on 09-11-2025 01:32 AM Edited on 09-11-2025 01:33 AM
Hi, thanks for your reply.
I could not find the Tag Types Being Shared option in the EMS, however that Tags are working in some Fortigates from the Fabric, from what I could see, the ones that does not work are the ones where I can not enable the ZTNA feature in the feature visibility.
Created on 09-11-2025 10:55 AM Edited on 09-11-2025 10:55 AM
can you share the FortiGate model and FortiOS running on those were the tags are no visible and cannot enable the ZTNA feature ?
Hi,
Fortigate 60F FortiOS 7.4.7
Hello,
I noticed that the problem seems to be related to the FortiGate not connecting properly to the fabric.
I am still having some trouble establishing the connection, but I believe that once this issue is resolved, the tags will appear correctly.
Thank you for your support.
| User | Count |
|---|---|
| 2737 | |
| 1418 | |
| 812 | |
| 739 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.