Fortinet ZTNA Proxy - FortiManager
Hi everyone,
We've recently started migrating a few services behind a proxy address using FortiEMS tags. Most of these services are simply websites (HTTPS), and about 95% of the resources work as expected. Since we are also using FortiManager for global firewall management, I had the idea to implement a similar setup.
On the EMS, I've created a few tags (such as Admin workstation, specific IP range/address, etc.). On the FortiGate, we set up a ZTNA server (HTTPS) with the FortiManager IP as the real server and created the corresponding ZTNA policy with tag filtering.
So far, so good. Accessing the FortiManager works as expected—the login page displays correctly, and logging in with local or SAML credentials works seamlessly. However, once I enter any ADOM, while I can see the number of managed FortiGates, nothing is displayed. No FortiGates show up in the managed view, and there's no access to logs (separate FAZ).
Interestingly, I can see our managed FAZ within the ADOM as a device. Am I missing something? Does this solution even work as intended? If anyone has any ideas or input, it would be greatly appreciated.
