Skip to main content
R_F
Explorer
November 29, 2022
Question

ZTNA inspection from LAN to DMZ

  • November 29, 2022
  • 4 replies
  • 1602 views

Dear Folks,

 

Seeking an ideal setup on how to enforce ZTNA for the segmented network. Let's say, I have my LAN users traffic destined for my DMZ or server farm that must be inspected by FG firewall policy with ZTNA parameters before the target resources become reachable.

 

any helpful insight is much appreciated.

4 replies

Anthony_E
Staff
Staff
December 2, 2022

Hello R_F,

 

Thank you for using the Community Forum.

I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Regards,

Best Regards
Anthony_E
Staff
Staff
December 5, 2022

Hello,

 

We are still looking for someone to help you.

We will come back to you ASAP.


Regards,

Best Regards
Anthony_E
Staff
Staff
December 6, 2022

Hello,

 

do you maybe have a contact to your regional TAC team?

They should maybe help you.

 

Regards,

Best Regards
pminarik
Staff
Staff
December 6, 2022

Hi R_F,

For internal endpoints, IP/MAC-based access control should be a good match. Have a look at the doc for it - https://docs.fortinet.com/document/fortigate/7.0.9/administration-guide/477578/ztna-ip-mac-based-access-control-example