Skip to main content
Explorer
May 8, 2026
Question

AGENTLESS ZTNA Troubleshooting

  • May 8, 2026
  • 1 reply
  • 149 views

Hello COMMUNITY,

I am facing some problems, I would really appreciate if you can assist me with that. I have installed fortigate on vmware on ubuntu and configured it per this document (https://docs.fortinet.com/document/fortigate/7.6.4/administration-guide/545125/ztna-agentless-web-based-application-access).
I added the fortigate ip (172.169.173.132) as portal.ztna.com to /etc/hosts to resolve the DNS. The issue is that web portal is not accessible. when I wrote the address to the browser, it shows 
 

  • with HTTP 
     

This page isn’t working

portal.ztna.com didn’t send any data.

ERR_EMPTY_RESPONSE

 

  • with HTTPS

This site can’t be reached

portal.ztna.com unexpectedly closed the connection.

Try:

  • Checking the connection
  • Checking the proxy and the firewall

ERR_CONNECTION_CLOSED

-----------------------------------------------------------

THIS IS MY CONFIGURATION

 

FGVMEVYLSWRHYA98 # show firewall vip 
config firewall vip
    edit "ZTNA-web-proxy"
        set uuid 65006b6c-42f6-51f1-97c1-5c559a60d09e
        set type access-proxy
        set server-type https
        set extip 192.168.173.132
        set extintf "port1"
        set client-cert disable
        set extport 15443
        set ssl-certificate "Fortinet_Factory"
        set ssl-algorithm high
        set ssl-min-version tls-1.2
    next
end

FGVMEVYLSWRHYA98 # show firewall access-proxy-virtual-host 
config firewall access-proxy-virtual-host
    edit "ztna-portal-vh"
        set ssl-certificate "Fortinet_Factory"
        set host "portal.ztna.com"
        set client-cert disable
    next
end

FGVMEVYLSWRHYA98 # show authentication scheme 
config authentication scheme
    edit "ztna-local-scheme"
        set method basic
        set user-database "local-user-db"
    next
end

FGVMEVYLSWRHYA98 # show authentication rule 
config authentication rule
    edit "ztna-portal-rule"
        set protocol ztna-portal
        set active-auth-method "ztna-local-scheme"
    next
end

FGVMEVYLSWRHYA98 # show ztna web-portal 
config ztna web-portal
    edit "portal1"
        set vip "ZTNA-web-proxy"
        set host "ztna-portal-vh"
        set auth-rule "ztna-portal-rule"
        set focus-bookmark enable
        set theme dark-matter
    next
end

FGVMEVYLSWRHYA98 # show ztna web-portal-bookmark 
config ztna web-portal-bookmark
    edit "my-bookmarks"
        set groups "ZTNA_USERS"
        config bookmarks
            edit "Google-Search"
                set url "https://google.com"
            next
        end
    next
end

FGVMEVYLSWRHYA98 # show firewall proxy-policy 
config firewall proxy-policy
    edit 1
        set uuid 93a3f4c6-479b-51f1-688f-622ff50cb61b
        set name "ztna-policy"
        set proxy ztna-proxy
        set ztna-proxy "portal1"
        set srcintf "any"
        set srcaddr "all"
        set dstaddr "all"
        set action accept
        set schedule "always"
        set logtraffic all
    next
end

---------------------

THE ISSUE

FGVMEVYLSWRHYA98 # diagnose debug enable

FGVMEVYLSWRHYA98 # [I][p:2721]               wad_unix_stream_on_read_msg       :553   recvmsg
[I][p:2721]               wad_unix_stream_on_read_msg       :553   recvmsg
[I][p:2721]               wad_tcp_port_alloc                :1482  alloc tcp_port=0x7f113fcc4048
[I][p:2721]               wad_accept                        :2420  redirect 92 accepted 192.168.173.1:55440 -> 192.168.173.132:15443 on 125
[I][p:2721]               wad_session_context_learn_v4_session:145   Redir session state=0x304 state2=0x1000000 state_ext=0x0.
[I][p:2721][s:5718]       wad_session_context_learn_session_config:495   vf_id=0 ses_ctx=0x7f113aae0a38 policy-id=0, sec_profile=(nil) app_type=http
     wan_opt_mode=0 av_idx=0 dd_method=0 wan_opt_tcp=0
     tp-mode=0 web_cache=0 webcache_ssl=0
     check_policy: http=0 ssh=0 ssh_tun=0 fw_ztna=0 ap=1
     ipsapp_redirect=0
     ssl_enabled=0 ssl_full=0 wanopt_ssl=0 ssl_proc=
     ses_ctx:t|Pv|M|H|C|A7|O fwdsvr=''
[I][p:2721][s:5718]       wad_ssl_port__open                :23549 port=0x7f113fcc4048 type=10 making SSL port
[V][p:2721][s:5718]       wad_ssl_negotiate_make            :2844  nego=0x7f113aa90c08
[I][p:2721][s:5718]       wad_ssl_port_inline_ips_init      :2665  wsp=0x7f113fcbc048/10 inline-ips disabled
[I][p:2721][s:5718]       wad_ssl_port__open                :23872 wsp=0x7f113fcbc048/10 SSL-port open succ type=10 port=0x7f113fcc4048 vd=0 svr=192.168.173.132:15443: succ
[V][p:2721][s:5718]       wad_tcp_port_out_read_block       :1030  tcp_port 0x7f113fcc4048 fd=125 on=0 n_out_block=1~>0 in(/out)_shutdown=0/0 closed=0 state=2.
[V][p:2721][s:5718]       wad_tcp_port_transport_read_block :987   tcp_port 0x7f113fcc4048 fd=125 on=0 n_out_block=1~>0 in(/out)_shutdown=0/0 closed=0 events=0x0.
[V][p:2721][s:5718]       wad_tcp_port_transport_read_block :1012  sock 125 read_block removed, turn on readability.
[I][p:2721][s:5718]       wad_ssl_port_run                  :23920 sp=0x7f113fcbc048/10 state=1
[V][p:2721][s:5718]       __wad_transparent_vs_manager_make :5619  vs(0x7f113f8a47c8/2) make(1).
[V][p:2721][s:5718]       wad_session_start_traffic_timer   :623   ses_ctx:0x7f113aae0a38 start traffic timer:3590
[I][p:2721][s:5718]       wad_tcp_port_alloc                :1482  alloc tcp_port=0x7f113fcc4190
[I][p:2721]               wad_tcp_port_put                  :630   free tcp_port=0x7f113fcc4190
[I][p:2721][s:5718]       wad_tcp_port_on_event             :1909  start processing tcp event=0x1 events=0x1 fd=125 n_out_block=0 state=2 close/shut=0/0 n_out_block=0
[I][p:2721][s:5718]       wad_tcp_port_on_read              :1780  sock 125 read (0,4072)
[2721] read [(0,1725) (16 03 01 06 b8 01 00 06 b4 03 03 af 0d ae 17 00 8e 18 93 09 5d 71 4d 7b 64 a3 b5 54 38 2b b4 bd fe 74 2d 76 13 f2 8b c1 d7 9a 3b 20 d4 47 0e c7 ad f4 6d da e3 08 43 66 1d e3 c6 db 32 01 81 1e cd 83 14 43 96 0d f3 9e 71 dc c6 67 00 20 9a 9a 13 01 13 02 13 03 c0 2b c0 2f c0 2c c0 30 cc a9 cc a8 c0 13 c0 14 00 9c 00 9d 00 2f 00 35 01 00 06 4b da da 00 00 00 0b 00 02 01 00 00 00 00 14 00 12 00 00 0f 70 6f 72 74 61 6c 2e 7a 74 6e 61 2e 63 6f 6d 00 2d 00 02 01 01 00 17 00 00 00 23 00 00 00 0a 00 0c 00 0a 8a 8a 11 ec 00 1d 00 17 00 18 00 33 04 ef 04 ed 8a 8a 00 01 00 11 ec 04 c0 d3 f8 b8 0f 81 5d 5b 15 a8 26 ba ad 6d 54 54 64 b0 90 1b 70 82 59 59 43 f7 6a c9 52 c6 78 da 5a ae 35 b7 63 d6 91 79 83 a9 47 1f 1c 0c 2a bc )(....................]qM{d..T8+...t-v......; .G....m...Cf....2......C....q..g. .........+./.,.0............./.5...K...................portal.ztna.com.-.........#...................3..................][..&..mTTd...p.YYC.j.R.x.Z.5.c..y..G...*.)]
     [(56 21 2a 45 29 b9 4a 5e b5 64 49 c6 75 8f 83 6c b1 54 5c 8e b5 c0 64 31 1d af 17 93 9d 5b 84 69 e6 cb 8f 94 07 94 5b 4d 86 24 b9 96 7a a6 71 9b 15 89 98 b9 0a 7b 17 08 90 1f 7f 53 0d 99 d8 4e 60 29 27 34 19 1c 9b 63 7d 7c ea 81 5e 96 44 98 f1 73 eb 6a 4f 19 7c 57 3f 29 88 ca d1 4a 77 1c ac ec 28 87 4d 22 cc 59 fb 82 a8 12 39 85 bb 76 b0 3a 9b 46 45 20 e8 65 c2 8a 86 04 25 a4 2a eb 10 04 55 c2 0d a4 47 9d f7 f8 c1 8a 2c 3a 23 6b 04 57 0a 0b e3 bb 8c da ea cf f3 b9 87 1b 2b c1 28 c7 65 84 80 4f bc ac 5f 8f 9c 15 3f d2 86 32 23 47 a5 83 4b 85 8c 69 9f b6 39 a6 f8 a5 fc 1c bf 15 10 9a 4b 79 bc 58 b5 90 1d 15 6f b7 20 ce 75 31 c7 92 d6 64 9a f0 39 62 19 2b a8 15 53 30 77 5e ec 9b cd f3 0c 06 fd a4 94 45 75 17 eb 07 )(V!*E).J^.dI.u..l.T\...d1.....[.i......[M.$..z.q......{.....S...N`)'4...c}|..^.D..s.jO.|W?)...Jw...(.M".Y....9..v.:.FE .e....%.*...U...G.....,:#k.W............+.(.e..O.._...?..2#G..K..i..9.........Ky.X....o. .u1...d..9b.+..S0w^.........Eu...)]

 

1 reply

RBA
Staff
Staff
May 10, 2026

Hi Steven4,

Screenshots shows error “ssl no matching CipherSuite, abort”

Just for testing can you set the max-version to tls1.2 and test.

config firewall vip
    edit ZTNA-web-proxy
        set ssl-max-version tls-1.2
    next
end

or set the TLS version to 1.3 on the PC and check. 

Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!