Skip to main content
desaia
Staff
Staff
October 24, 2024

Troubleshooting Tip: Unable to configure ZTNA firewall policy when central NAT is enabled

  • October 24, 2024
  • 0 replies
  • 840 views
Description This article describes how to configure ZTNA firewall policy when central NAT is enabled.
Scope FortiOS 7.2.5 and above.
Solution

FortiGate with multiple VDOMs and central NAT disabled will have the ZTNA firewall policy under 'Policy & Objects -> Firewall Policy'.

 

1.jpg

 

With central NAT enabled, there is no option to configure ZTNA policy under 'Policy & Objects -> Firewall Policy'.

 

2.jpg

 

To configure a ZTNA policy, explicit proxy needs to be enabled. The feature can be enabled under 'System -> Feature Visibility -> Explicit Proxy'.
The ZTNA policy is available under 'Policy & Objects -> Proxy Policy'.

 

3.jpg