Skip to main content
epinheiro
Staff
Staff
June 8, 2026

Technical Tip: ZTNA SSH using IP address may fail in non-proxy mode on macOS 26.3.1

  • June 8, 2026
  • 0 replies
  • 97 views

Description


This article describes an issue where ZTNA TCP forwarding fails on macOS 26.3.1 (Tahoe) systems running FortiClient. This behavior occurs when attempting to connect to a destination via an IP address on Port 22 (typically SSH) while operating in non-proxy mode.


Symptons:

  • ZTNA connection to Port 22 fails when the destination is defined by an IP address.

  • The connection times out or is rejected by the FortiClient ZTNA daemon.

  • Other ports or proxy-based ZTNA rules may continue to function as expected.

  • This behavior is specific to the macOS 26.3.1 (Tahoe) release.


Scope


FortiGate, FortiClient versions 7.4.5-7 and 8.0, MacOS version 26.3.1 (Tahoe).


Solution


As a workaround, modify the ZTNA destination rule to use an FQDN instead of an IP address.

  • Ensure the destination server has a resolvable DNS entry.

  • In the FortiGate (ZTNA Server) or EMS configuration, update the ZTNA Connection rule:

    • Old Setting: Destination IP: 192.168.1.50. Port: 22.

    • New Setting: Destination Host: server01.internal.corp. Port: 22.

Note: This issue is currently under investigation by the engineering team under Bug ID #1269678.