Skip to main content
msolanki
Staff
Staff
June 24, 2026

Troubleshooting Tip: Troubleshooting ZTNA TCP forwarding for public servers with sub-domain

  • June 24, 2026
  • 0 replies
  • 37 views

Description

This article describes the troubleshooting steps for Zero Trust Network Access (ZTNA) TCP forwarding issues when accessing public servers along with FQDN. The user may experience issues with some websites not being accessible despite having a working ZTNA setup.

Scope

FortiGate, FortiClient, FortiClient EMS.

Solution

To troubleshoot ZTNA TCP forwarding issues for public servers which has FQDN with multiple subdomain, follow these steps:


  1. Verify that the ZTNA configuration is correct and that the destination IP address is properly resolved. For more details, see Technical Tip: How to implement ZTNA TCP forwarding for public servers hosted on the Document360 platform, given that Document360 enforces IP-based access restrictions.

  2. Verify that the proxy policy is correctly configured. If a flow-based policy is in use, try configuring a proxy policy instead.

  3. If the issue persists, try adding a new ZTNA destination with the correct domain. Refer to the Full versus simple ZTNA policies for more information on configuring ZTNA policies.

  4. If the issue remains unresolved, check the real server FQDN and its resolved IP address. It is possible that the application is being served from a different subdomain that has not been configured under the Access Proxy real server settings ('config real servers').

  5. To resolve the issue, either the specific subdomain must be configured under the Access Proxy real server settings, or the existing FQDN configuration should be modified to include the correct domain being used by the application.


The following log entries are seen in the debug output:

[r:139] wad_http_req_check_policy_with_flags:12112 start match policy vd=0(ses_ctx:ct|P|M|H|C|A1|O) (85.3.190.20:51354@3->208.79.209.138:443@3) absUrl=0
I][p:2758][s:55835][r:139] wad_http_policy_match_one :498 fw_pol_id=11(pol_ctx:th|Ad|7|=p) pflag:H|W|U|A asyn_info=1
[V][p:2758][s:55835][r:139] wad_fw_addr_match_ap :1293 matching ap:Ressources-Bib(14) with vip addr:Ressources-Bib(14)
[V][p:2758][s:55835][r:139] wad_fw_policy_set_check_id :5817 pol_id=11 dev_cked=0
[V][p:2758][s:55835[r:139]wad_http_parse_dev_relay_from_hdr :11925 Invalid fos-auth header