Hi Fortinet Community,
I'm currently using FortiClient EMS 7.4 and FortiGate running FortiOS 7.4. When I try to access a server located in the DMZ using ZTNA access policies with ZTNA tags, I receive the following error:
Despite this, everything seems fine on the FortiGate side:
I can't identify where the issue is happening—whether it's on the client, EMS, or FortiGate.
Has anyone encountered this issue or have suggestions on what else I should check?
Appreciate any help or guidance from the community!
Thanks.
Solved! Go to Solution.
Hi @atakannatak ,
I have identified the issue.
I had previously installed a custom EMS CA certificate (ZTNA). After removing it and reverting to the default certificate, ZTNA access started working as expected.
Best regards.
Sadhi
Hi @Sadhi_Jayz ,
Error 066 (“No device information found”) indicates the FortiGate did not receive the endpoint-identity header from FortiClient, so it cannot match the HTTPS request to a device record and therefore denies the ZTNA policy. The FortiClient agent is not injecting the header—most often because the ZTNA connection rule (FQDN/port) does not match the URL the user is accessing, the ZTNA certificate pairing is broken, or the client is not in a “ZTNA Connected” state.
The following debug commands can be used to further more analysis:
To see if the device record or tag updates arrive run real-time fcnacd debugs:
Troubleshoot WAD in real time to see how the proxy handles client requests:
Once we have the captured output, we can trace exactly how wad handled each request and pinpoint the root cause.
BR.
If my answer provided a solution for you, please mark the reply as solved it so that others can get it easily while searching for similar scenarios.
CCIE #68781
Hi @atakannatak ,
I have identified the issue.
I had previously installed a custom EMS CA certificate (ZTNA). After removing it and reverting to the default certificate, ZTNA access started working as expected.
Best regards.
Sadhi
User | Count |
---|---|
2567 | |
1358 | |
796 | |
650 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.