Skip to main content
bilal113
New Member
January 28, 2026
Question

FORTISASE ZTNA AGNET BASED & AGENT LESS ISSUE

  • January 28, 2026
  • 3 replies
  • 405 views

Hi Everyone,

 

I am deploying Fortisase and trying to deploy ZTNA Agent based & Agent less 

 

We are currently experiencing an issue with Fortinet SASE ZTNA agentless access. Despite having completed the following configurations, the bookmark portal is not accessible unless the ZTNA agent is connected:

 

Proxy has been enabled

 

Proxy SSO is configured and active

 

Application and corresponding application policy have been created Bookmark portal has been set up and published the bookmark portal link works as expected when the ZTNA agent is connected but fails to load or authenticate when accessed in agentless mode—despite all prerequisites appearing to be correctly configured.

 

Can anyone please assist us in troubleshooting this issue? We would appreciate your guidance on whether potential bug affecting agentless access in our PORTAL

 

 

3 replies

Stephen_G
Staff & Editor
Staff & Editor
January 30, 2026

Hello bilal113,

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.

Stephen_G - Fortinet Community Team
Stephen_G
Staff & Editor
Staff & Editor
February 3, 2026

Hello,

 

We are still looking for an answer to your question.

 

We will come back to you ASAP.

Stephen_G - Fortinet Community Team
Stephen_G
Staff & Editor
Staff & Editor
February 5, 2026

Hello again,

 

I received this answer. Please let me know if it helps:

 

-----------

 

To troubleshoot the issue with Fortinet SASE ZTNA agentless access, let's go through a few steps and considerations:

1. Verify Prerequisites and Configuration:

  • Licensing: Ensure that the FortiSASE has the appropriate license (Advanced, Professional, or Comprehensive remote users license) applied.
  • Proxy and SSO Configuration: Confirm that the proxy and proxy SSO are correctly configured. This includes ensuring that the SAML IdP is set up properly for user authentication.
  • SPA Configuration: Ensure that Secure Private Access (SPA) is configured for the FortiGate device acting as the SPA hub.
  • Private Application Configuration: Verify that the private web-based application is correctly configured to reside on the local network behind a FortiGate device and supports HTTPS.

2. Check Agentless ZTNA Limitations:

  • Proxy and Agent Users: Note that proxy and agent users cannot access private application bookmarks configured for agentless ZTNA.
  • SPA Hubs and FQDN: Agentless ZTNA does not work with SPA hubs configured with BGP on loopback and private web-based applications configured with the Server Type set to FQDN.

3. Debugging Steps:

  • WAD CLI Debug Commands: Use the following WAD CLI debug commands to gather more information. Replace 'x.x.x.x' with the remote client's public IP address:
    diagnose debug reset diagnose wad filter src x.x.x.x diagnose wad debug category 

4. Known Issues:

  • Version-Specific Issues: If you are using FortiGate devices running version 7.6.x, there are known issues with ZTNA agentless access on certain devices like the 90G. Ensure that your device and version are not affected by these known issues.

5. Additional Considerations:

  • Browser Cache: Ensure that the browser cache is cleared, as deauthenticating a proxy SSO user does not direct the user to reauthenticate without clearing the cache first.
  • Deep Inspection: For proxy SSO users, ensure that at least one proxy policy using SSO authentication has deep inspection enabled in the configured security profile group.

Final Thoughts:

If the above steps do not resolve the issue, it may be beneficial to check for any updates or patches that address known bugs in the version you are using. Additionally, consider reaching out to Fortinet support for further assistance, as they may have more specific insights into potential bugs affecting agentless access in your portal.

Stephen_G - Fortinet Community Team
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!