Technical Tip: A solution of the error 'ZTNA Traffic denied because HTTP url failed to match an API-gateway with vhost name'
Description | This article describes a solution to fix the ZTNA access-proxy issue when using SAML authentication. Indeed, the ZTNA traffic log shows an error 'ZTNA Traffic denied because HTTP url failed to match an API-gateway with vhost name', after upgraded FortiOS firmware from v7.6.0 to v7.6.2.
|
Scope | Â FortiOS v7.6.1 or later. |
Solution | The issue happens due to the change from FortiOS v7.6.1 onward, when FortiGate Firewall will implicitly create a virtual-host with the domain defined in the SAML server configurations. It requires defining access-proxy-virtual-host and define it in the API Gateway of ZTNA access-proxy to work again: |
