Hello EMS admins
EMS 7.4.1 and FOS 7.2.10.
When I put EMS VM in a VLAN attached to FGT, the clients' tags are updated correctly, and we can see the tags of each connected client under Policy & Objects > ZTNA > ZTNA Tags.
However when I put a firewall between my FG and the EMS, the fabric connector connects successfully and we can see the shared tags, but we can't see the tags of the connected clients anymore.
Note that I opened the required ports from the FGT to EMS, like 8013, 8015 and 443.
Does it mean it is a requirement to put EMS in a VLAN directly connected to FG, or did I miss something?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
The FGT<--->EMS path shouldn't matter, the FGT<--->FCT should. Any chance you're accidentally(?) also adding the router in-between the FGT and FCTs? As far as I know EMS by default only shares info about FortiClients whose gateway MAC matches any of the FGT's interfaces.
Thanks for your response, Minarik.
This is not the case. It seems the issue occurs only when I add a firewall between EMS & FGT.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1710 | |
1093 | |
752 | |
446 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.