Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
AEK
SuperUser
SuperUser

Router between EMS and FGT

Hello EMS admins

EMS 7.4.1 and FOS 7.2.10.

When I put EMS VM in a VLAN attached to FGT, the clients' tags are updated correctly, and we can see the tags of each connected client under Policy & Objects > ZTNA > ZTNA Tags.

However when I put a firewall between my FG and the EMS, the fabric connector connects successfully and we can see the shared tags, but we can't see the tags of the connected clients anymore.

Note that I opened the required ports from the FGT to EMS, like 8013, 8015 and 443.

Does it mean it is a requirement to put EMS in a VLAN directly connected to FG, or did I miss something?

AEK
AEK
2 REPLIES 2
pminarik
Staff
Staff

The FGT<--->EMS path shouldn't matter, the FGT<--->FCT should. Any chance you're accidentally(?) also adding the router in-between the FGT and FCTs? As far as I know EMS by default only shares info about FortiClients whose gateway MAC matches any of the FGT's interfaces.

[ corrections always welcome ]
AEK

Thanks for your response, Minarik.

This is not the case. It seems the issue occurs only when I add a firewall between EMS & FGT.

AEK
AEK
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors