Skip to main content
raffaeledp
Explorer III
February 17, 2025
Solved

Is it possible to include a ZTNA tag inside a local-in policy?

  • February 17, 2025
  • 5 replies
  • 1358 views

hello everybody, I defined a ZTNA Group that includes two ZTNA Tags:

 

Screenshot 2025-02-17 alle 18.10.14.png

 

I know that a firewall policy can work with ZTNA Tags. But is it the same for a local-in-policy?

Looking at the documentation:

 

config firewall {local-in-policy | local-in-policy6}     edit <policy_number>         set intf <interface>         set srcaddr <source_address> [source_address] ...         set dstaddr <destination_address> [destination_address] ...        set action {accept | deny}         set service <service_name> [service_name] ...         set schedule <schedule_name>         set comments <string>     next end

 

It generally talks about a destination address. But is the local-in-policy capable of understanding a ZTNA group?

I didn't find anything indicative about this. I'm working on a Fortigate 60F v7.2.11.

Thank you

Best answer by AEK

Hi Raffael

As per my knowledge you can't.

But depending on what you want to achieve you may transform your local-in policy to a firewall policy using a loopback address.

5 replies

AEK
SuperUser
AEKAnswer
SuperUser
February 18, 2025

Hi Raffael

As per my knowledge you can't.

But depending on what you want to achieve you may transform your local-in policy to a firewall policy using a loopback address.

AEK
AEK
SuperUser
SuperUser
February 18, 2025
Yurisk
SuperUser
SuperUser
February 18, 2025

ZTNA in Local-in policy ? Nope, not possible yet, but give Fortinet folks a break - they just (7.2) introduced Geo address object and ISDB (7.4.4) in Local-in policy, and already asking for ZTNA :) ... 

Some day probably ...

 

Thanks @AEK for the mentioning.

 

yurisk.info - all things Fortinet blog, no ads
AEK
SuperUser
SuperUser
February 18, 2025

@raffaeledp 

I just want to clarify that by the example above I mean you can see how you can transform your local-in policy to a firewall policy using a loopback address, and you can then use ZTNA tag to access the FGT resource (admin UI, ssh, VPN and so).

AEK
MZBZ
Staff
Staff
February 20, 2025
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!