Hello EMS admins
EMS 7.4.1 and FOS 7.2.10.
When I put EMS VM in a VLAN attached to FGT, the clients' tags are updated correctly, and we can see the tags of each connected client under Policy & Objects > ZTNA > ZTNA Tags.
However when I put a firewall between my FG and the EMS, the fabric connector connects successfully and we can see the shared tags, but we can't see the tags of the connected clients anymore.
Note that I opened the required ports from the FGT to EMS, like 8013, 8015 and 443.
Does it mean it is a requirement to put EMS in a VLAN directly connected to FG, or did I miss something?
The FGT<--->EMS path shouldn't matter, the FGT<--->FCT should. Any chance you're accidentally(?) also adding the router in-between the FGT and FCTs? As far as I know EMS by default only shares info about FortiClients whose gateway MAC matches any of the FGT's interfaces.
Thanks for your response, Minarik.
This is not the case. It seems the issue occurs only when I add a firewall between EMS & FGT.
User | Count |
---|---|
1923 | |
1144 | |
769 | |
447 | |
279 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.