FortiClient
FortiClient proactively defends against advanced attacks. Its tight integration with the Security Fabric enables policy-based automation to contain threats and control outbreaks. FortiClient is compatible with Fabric-Ready partners to further strengthen enterprises’ security posture.
aliyavuzer
Staff
Staff
Article Id 290871
Description This article describes how to get Endpoint IP/MAC Details to the FortiGate dynamic list by ZTNA.
Scope FortiClient, FortiGate, ZTNA, EMS.
Solution

FortiClient EMS Shares endpoint IP and MAC address to FortiGate by ZTNA Tag. But while listing the endpoint IP and Mac address on the Firewall endpoint default gateway should point to the desired Firewall.

Client default gateway address must be FortiGate or the Client should be connected to FortiGate by VPN tunnel.

 

Related document:

FortiOS dynamic policies using EMS dynamic endpoint groups 

 

To see all endpoint details on the FortiGate, switch the following option from EMS: EMS -> Administration -> Fabric Devices -> Edit Fabric Device -> Switch '

 

Fabric Device FortiGate FortiClient Endpoint SharingFabric Device FortiGate FortiClient Endpoint Sharing

 

 

Then navigate to FortiGate -> Policy & Objects ->  ZTNA -> ZTNA Tags and check resolved Addresses for the desired tag.

 

In the screenshot, the endpoint is not connected to the VPN, and the default Gateway does not point to the FortiGate but the endpoint IP addresses listed under the ZTNA tag.

 

Endpoint detailsEndpoint details

 

Tag details on FortiGateTag details on FortiGate

 

 

For checking IP details in CLI:

 

diagnose firewall dynamic list

Contributors