Skip to main content
zoriax
New Member
March 25, 2022
Question

ZTNA Tags IP/MAC are empty

  • March 25, 2022
  • 12 replies
  • 10745 views

Hello everyone,

 

I'm really suggering with ZTNA :( :) 

 

I tried to get IP/MAC informations inside my ZTNA tags on FortiGate. I configured corretly EMS / Forticlient and Fortigate. My tags are sync successfully but the are emtpy 

 

On my fortiGate, my device is correctly registred : 

zoriax_1-1648199260879.png

My tag is correctly added : 

zoriax_2-1648199290686.png

But when I looked inside it on my FortiGate, the tag is definitevly empty : 

zoriax_3-1648199331895.png

I don't know what I can do to correctly sync device information with my fortigate. I'm sure it's simple but I can't find how.

 

I really need your help ! 

 

Thanks

 

 

 

12 replies

zoriax
zoriaxAuthor
New Member
March 25, 2022

I'm sure I mistaken somewhere.... But what is the correct way to sync/send IP and MAC address in tags to my FortiGate.

amouawad
Staff
Staff
March 26, 2022

By default the EMS doesn't send ZTNA tags for devices that are off-net. You have two options here.

1. If the device is on the network then you can create on-net rules to trigger the device to be on-net status which will update the ZTNA tags.

2. You can configure EMS to send IPs for devices that are off-net. Edit the FGT in EMS (Administration > Fabric Devices) and uncheck "Filter tag IPs from specific FortiGates". The EMS will now send off-net IP addresses to the FGT. This is generally not recommended as you may get alot of off-net IP addresses for devices that are not on the network.

zoriax
zoriaxAuthor
New Member
March 28, 2022

Hello,

 

I can't see option "Filter tag IPs from specific FortiGates" but here is what I share from EMS : 

 

zoriax_0-1648446561218.png

It's really strange because all seems to work fine but my tags stay empty on my fortigate... 

 

Do you have another suggestion ? Thanks

 

zoriax
zoriaxAuthor
New Member
March 28, 2022

I tried to configure an "on-net" rule but same behaviour... My tags stay empty and it drives me crazy :-)....

zoriax
zoriaxAuthor
New Member
March 28, 2022

Maybe one important information. The FortiGate where tags are sync is not my primary default gateway. It's maybe why IP/Mac are not sync correctly. 

 

What I tried to do is to sync ZNAT Tags from remote client (trough VPN) : 

Remote Client -> VPN -> FortiGate (VPN, ZNAT Tags) -> Netowork (EMS, Server1, Server2, ...)

 

1) Is it possible to "sync" remote client IP in ZNAT trought VPN ? 

2) Is it possible to use Firewall policies based on ZNAT Tags and IP ? 

 

It's strange because when my device is connected trough VPN, I can see some informations in my FortiGate but not all, and my device is seen as offline...

 

IP Address = 192.168.0.1
MAC Address = 00:00:00:00:00:00
MAC list =
VDOM = root (0)
EMS serial number:
Client cert SN:
Public IP address: 0.0.0.0
Quarantined: no
Online status: offline
Registration status: not registered
On-net status: off-net

 

Thanks

 

 

zoriax
zoriaxAuthor
New Member
March 28, 2022

After some search and as I can see, the forticlient muts be connected (as default gw) to the fortigate. So it's mybe why tags are not correct. But, why when I'm connected trough my VPN my tags are not updated ?

zoriax
zoriaxAuthor
New Member
March 29, 2022

So after a lot of search, the "sync" problem appears only when my devices are connected trought VPN. 

So how can I sync tags and devices when they are connected trough VPN tunnel ? 

amouawad
Staff
Staff
March 29, 2022

What type of VPN are you using to connect the clients? I've just tested connecting through an SSLVPN and can confirm that the tags get populated on the EMS/FGT.

 

Below you can see the 'linux' ZTNA tag being populated with the IP address of 10.212.134.200 which is the IP address of the client when it connects via SSLVPN:

Linux ZTNA tag on FGT populated with the SSLVPN IP addressLinux ZTNA tag on FGT populated with the SSLVPN IP addressFortiClient with Linux ZTNA tag and SSLVPN IP addressFortiClient with Linux ZTNA tag and SSLVPN IP address

 

FYI in my setup I'm using the following versions:

 

FGT: 7.0.5

EMS: 7.0.3

FCT: 7.0.3

FlavioB1
Explorer III
November 3, 2022

Hi there.

I'm having a similar situation.

EMS 7.0.7

FCT 7.0.7

FGT 6.4.8

FMG 7.0.4

 

I have the EMS address objects both on the FMG and on the FGT, but they do not get populated at all. The FCTs needing to populate them are connecting via SSLVPN.

 

Any help on this?

Thanks!

zoriax
zoriaxAuthor
New Member
March 29, 2022

I tried with IPSec VPN tunnel in my case. Effectively it seems to work with SSL but why not with IPSec ?

 

Thanks

amouawad
Staff
Staff
March 29, 2022

For the sake of complete testing, the above test was done on a FCT that was On-Net/On-Fabric. I've tested with the device Off-Net/Off-Fabric and can confirm that the IP addresses still get updated correctly.

 

2022-03-29_23-49.pngFCT Off-Net, connecting via SSLVPNFCT Off-Net, connecting via SSLVPN