Skip to main content
Fullmoon
New Member
July 14, 2021
Question

ZTNA

  • July 14, 2021
  • 5 replies
  • 6388 views

does anyone here tried to configured their existing FG and FortiEMS for ZTNA setup?

    5 replies

    skyegool
    New Member
    July 15, 2021

    Hi,

     

    I did, tags worked awesome before, ZTNA added complexity, and you cant activate it via GUI (bug)

    You must enable it via CLI

     

    config firewall policy edit <ID> set ztna-status enable set ztna-ems-tag <ZTNA_TAG_NAME? next end

     

     

     

    Fullmoon
    FullmoonAuthor
    New Member
    July 22, 2021

    skyegool wrote:

    Hi,

     

    I did, tags worked awesome before, ZTNA added complexity, and you cant activate it via GUI (bug)

    You must enable it via CLI

     

    config firewall policy edit <ID> set ztna-status enable set ztna-ems-tag <ZTNA_TAG_NAME? next end

     

    thanks for the response mate. So having FG and EMS/FortiClient are good enough for ZTNA setup?

     

     

     

    martin28
    New Member
    May 18, 2022

    It does not work for me, traffic not matching the policy.

    peisenberg
    Staff
    Staff
    September 5, 2022

    Hi @Fullmoon 

    Sorry for late response. Do you still need help with ZTNA ?

    Pavol

    shaibal_mitra
    New Member
    January 13, 2023

    We are deploying ztna for the first time with fortisase and have had nothing but problems so far.Only RDP works and that takes for ever to load up.ssh does not work.Also using any ztna tags in policy breaks everything.Version is 7.0.9.

    peisenberg
    Staff
    Staff
    January 17, 2023

    Hello

    Can you please log a TAC ticket so we can assist you with your issue  ?

    Thanks

     

    Pavol

     

    peisenberg
    Staff
    Staff
    January 17, 2023

    Hello

    Can you please log a TAC ticket so we can help you further ?

    thanks

    Pavol