Skip to main content
AEK
SuperUser
SuperUser
December 8, 2024
Question

Source address in ZTNA proxy policy

  • December 8, 2024
  • 3 replies
  • 955 views

Hi EMS/FGT admins

When creating ZTNA proxy rule (in Policy & Object > Proxy Policy) for clients that are off-fabric, is there anything valid that we can put in "Source" field other than "all"?

Trying to put the public source address of the client, or even the client's private source address behind its router, but nothing seem to match, only "all" works. It seems srcaddr in ZTNA proxy rules means something different than in standard rules, but can't find what.

Any idea?

3 replies

sjoshi
Staff
Staff
December 8, 2024

Hi,

 

Can you share the snapshot of the proxy policy setup for better clarity

Thanks, Salon
sjoshi
Staff
Staff
December 8, 2024

setting up private IP should work as in the wad debug you will see the traffic coming with the private PC ip

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Sample-configuration-Proxy-ZTNA/ta-p/242053

Thanks, Salon
AEK
SuperUser
AEKAuthor
SuperUser
December 8, 2024

Hi Joshi

Thanks for your response.

Here is the screenshot:

ztan_proxy_rule.png

 

On the tech tip you shared, they are also using "all" as source address in the ZTNA rule.

AEK