Created on
‎11-29-2023
12:20 AM
Edited on
‎08-11-2025
02:39 AM
By
Anthony_E
Description | This article provides a list of the commands when encountering a ZTNA tagging issue that involves FortiGate, EMS, and FortiClient. |
Scope | FortiGate v7.0.12+.,EMS v7.0.7+.v7.0.7+. |
Solution |
On the FortiGate CLI:
diagnose endpoint ztna-shm list
diagnose de crashlog read
FCNAC:
diagnose debug application fcnacd -1 diagnose debug console timestamp enable diagnose endpoint filter show-large-data yes diagnose debug enable
Disable debug:
diagnose debug disable diagnose debug reset
WAD:
diagnose debug reset diagnose wad filter src x.x.x.x diagnose wad filter dst x.x.x.x diagnose wad debug enable category all diagnose wad debug enable level verbose diagnose debug enable
Disable debug:
diagnose debug disable diagnose debug reset
From v7.4.2, 'diagnose endpoint record list' has been changed to 'diagnose endpoint ec-shm list'.
From v7.6.0, TAG will be reflected in forward traffic logs. Refer to the below document for more information: Include EMS tag information in traffic logs
C:\Program Files (x86)\Fortinet\FortiClientEMS\logs |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.