Technical Tip: ZTNA SSH using IP address may fail in non-proxy mode on macOS 26.3.1
Description
This article describes an issue where ZTNA TCP forwarding fails on macOS 26.3.1 (Tahoe) systems running FortiClient. This behavior occurs when attempting to connect to a destination via an IP address on Port 22 (typically SSH) while operating in non-proxy mode.
Symptons:
ZTNA connection to Port 22 fails when the destination is defined by an IP address.
The connection times out or is rejected by the FortiClient ZTNA daemon.
Other ports or proxy-based ZTNA rules may continue to function as expected.
This behavior is specific to the macOS 26.3.1 (Tahoe) release.
Scope
FortiGate, FortiClient versions 7.4.5-7 and 8.0, MacOS version 26.3.1 (Tahoe).
Solution
As a workaround, modify the ZTNA destination rule to use an FQDN instead of an IP address.
Ensure the destination server has a resolvable DNS entry.
In the FortiGate (ZTNA Server) or EMS configuration, update the ZTNA Connection rule:
Old Setting: Destination IP: 192.168.1.50. Port: 22.
New Setting: Destination Host: server01.internal.corp. Port: 22.
Note: This issue is currently under investigation by the engineering team under Bug ID #1269678.
