Skip to main content
alansims
New Member
April 26, 2025
Question

Replacing SSL-VPN with ZTNA?

  • April 26, 2025
  • 5 replies
  • 2013 views

Hi. I've been a user of SSL-VPN until it was removed from the latest firmware.

I've clients using ubuntu linux variants and have problems setting IPSEC for them via strong swan. 

Any advice if switching to ZTNA would solve most issues?

I presume I can install this "ZTNA Forti s/w" on linux?

Would just getting a ZTNA licence be enough? What about the configuration of EMS. How is it done?

 

Another question I have is I've 2 Fortinet. 

Fortinet 1 has a public uplink and serves some services in the clear.

It has a port that is attached to Fortinet 2 that turns on and off.

Fortinet 2 serves services in a locked-down environment. 

Would I be able to have ZTNA running on Fortinet2 having Fortinet1 as an uplink?

End state is my users be able to connect to Fortinet1 and Fortinet2 one at a time to use services in both networks.

5 replies

AEK
SuperUser
SuperUser
April 26, 2025

Hi Alan

 

For strongSwan under Linux check this tech tip.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-IPsec-connection-between-FortiGate-and-Ubuntu-via/ta-p/207149

 

For ZTNA configuration (EMS), if you are not familiar with EMS integration then you better call a Fortinet partner, as it requires some skills.

 

Typical case is to configure ZTNA gateway on the front-end firewall. Or I may not understand well what are you looking for.

AEK
alansims
alansimsAuthor
New Member
April 28, 2025

Just wondering if you know if 2FA works on the strong swan?

AEK
SuperUser
SuperUser
April 28, 2025

2FA is supported since strongSwan supports at least ssl certificate.

If you mean OTP token, then in theory any client supports 2FA, either by RADIUS challenge or by password+token concatenation.

AEK
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!