Technical Tip: Why re-authentication is needed in a IPsec / ZTNA Access environment when a client's IP address changes
Description | This article describes the reasons for re-authentication requests in an IPsec / ZTNA Access environment when client's IP address changes. |
Scope | FortiGate, FortiClient, FortiClient EMS. |
Solution | In environments where both IPsec VPN and ZTNA Access Proxy are used, frequent changes in the client's IP address can trigger new authentication processes. This behavior is expected due to the following reasons:
This is an expected behavior due to security design, not a misconfiguration. VPN ties sessions to IP -> IP change = new session. ZTNA enforces continuous trust -> context change = re-validation. ISP instability amplifies both In short: Dynamic IP + Zero Trust + IPsec = frequent re-authentication. |
