Created on 01-14-2024 10:45 PM Edited on 01-14-2024 10:45 PM By Anthony_E
Description | This article describes how to get Endpoint IP/MAC Details to the FortiGate dynamic list by ZTNA. |
Scope | FortiClient, FortiGate, ZTNA, EMS. |
Solution |
FortiClient EMS Shares endpoint IP and MAC address to FortiGate by ZTNA Tag. But while listing the endpoint IP and Mac address on the Firewall endpoint default gateway should point to the desired Firewall.
Related document: FortiOS dynamic policies using EMS dynamic endpoint groups
To see all endpoint details on the FortiGate, switch the following option from EMS: EMS -> Administration -> Fabric Devices -> Edit Fabric Device -> Switch '
Then navigate to FortiGate -> Policy & Objects -> ZTNA -> ZTNA Tags and check resolved Addresses for the desired tag.
In the screenshot, the endpoint is not connected to the VPN, and the default Gateway does not point to the FortiGate but the endpoint IP addresses listed under the ZTNA tag.
For checking IP details in CLI:
diagnose firewall dynamic list |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.