Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Andizer
New Contributor II

EMS TAG synchronisation Problems

Hello,


the content of the ZTNA tags synced from the EMS server to Fortigate is incomplete.

This means that the corresponding firewall policies do not work correctly as some tagged clients are missing.

However, I can find the clients with the correct tags on the EMS server

 

Fortigate OS v7.0.14 build0601 (Mature)

 

Maybe someone else here has this problem and was able to solve it 

 

Thanks

4 REPLIES 4
AEK
SuperUser
SuperUser

Hi @Andizer 

One possible cause is when you use some special characters in the tag name. I had a similar issue when I used "#" in tag name and it not only blocked the tags, but I couldn't even remove this tags from FGT. Only support could fix it with special commands.

AEK
AEK
Andizer
New Contributor II

Thanks for your idea.

Sadly this is not the case for us, using this format "no special characters" (only using a space between)

hbac
Staff
Staff

Hi @Andizer,

 

Please refer to this article to collect debugs: https://community.fortinet.com/t5/ZTNA/Troubleshooting-Tip-ZTNA-tagging-issue-debugging-commands/ta-...

 

Regards, 

Sheikh
Staff
Staff

Hello @Andizer ,

 

Have you tried force sycn (restarting) the ZTNA tags between FGT and EMS?
diagnose test application fcnacd 99

In another session, enable these logs to show output.
diagnose debug application fcnacd -1 
diagnose endpoint filter show-large-data yes
diagnose debug enable

 

regards,

 

Sheikh

**If you come across a resolution, kindly show your appreciation by liking and accepting it, ensuring its accessibility for others**
Labels
Top Kudoed Authors