Skip to main content
Akmostafa
Explorer
August 5, 2025
Question

ZTNA in windows domain infrastructure and client-to-domain-controller traffic

  • August 5, 2025
  • 6 replies
  • 1302 views

Hello Folks,

 

windows environment seem to be somehow complex to me when dealing with ZTNA, especially when knowing that some transactions need line-of-side connections between clients and the DC, many ports being used on both TCP and UDP.

 

In my scenario, I have configured a ZTNA server to the LDAP, included all ports required. UDP seem to work, cause I have tried to resolve names from the client side. However, when it comes to the user login (with a new username that is not cached on the client machine or after resetting a domain user`s password), things not working.

 

I have seen this kb about the need for a KDC proxy for accessing shared folders. Do I need a KDC also to allow users to login to their machines when they are at home (especially after a password change?)

 

ZTNA access proxy with KDC to access shared drives | FortiGate / FortiOS 7.4.1 | Fortinet Document Library

 

Secondly, for the sake of troubleshooting, sometimes I needed to analyze packets from the fG to the backend servers while preserving the client`s IP address. I have found the below document but it did not help because it talks about editing a proxy policy, while in 7.4, ztna configurations are under ordinary firewall policy , even when I tried to disable the NAT, I Stil cannot see traffic between the firewall and backend server when performing a sniffer (filtered by client IP address and backend server ip address)

 

Using the IP pool or client IP address in a ZTNA connection to backend servers | FortiGate / FortiOS 7.2.0 | Fortinet Document Library

6 replies

Jean-Philippe_P
Staff & Editor
Staff & Editor
August 8, 2025

Hello Akmostafa, 

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible. 

 

Thanks, 

Jean-Philippe - Fortinet Community Team
Anthony_E
Staff
Staff
August 11, 2025

Hello,

We are still looking for someone to help you.

We will come back to you ASAP.


Thanks,

Best Regards
Anthony_E
Staff
Staff
August 19, 2025

Hello,

 

Sorry for the delay, we are still looking for someone to help.

 

Regards,

Best Regards
Anthony_E
Staff
Staff
August 20, 2025

Hello,

 

May I invite you to open a ticket from our support portal?: https://support.fortinet.com/welcome/

 

Regards,

Best Regards
Akmostafa
AkmostafaAuthor
Explorer
August 20, 2025

Already done that.

But it seems there is lack of documentation regarding this topic.

Anthony_E
Staff
Staff
August 20, 2025

Do you maybe have a solution to share here?

 

Regards,

Best Regards
funkylicious
SuperUser
SuperUser
August 20, 2025

hi,

in 7.4 you can configure the ZTNA rules under Explicit Proxy/Proxy Policy as per this instead of classic firewall rules.

"jack of all trades, master of none"