FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Rathan_FTNT
Staff
Staff
Article Id 200435
Description When configuring a ZTNA server, load balancing, TCP forwarding, and SAML can be configured from GUI.
Scope For v7.0.2 and above.
Solution

Load balancing.

 

Load balancing can be configured when adding or editing a service or server mapping.

 

Rathan_FTNT_0-1638861507020.png

 

 

When adding a load balancing server:

- If the load balancing method is Weighted then the weight can be included.

 

- If the method is HTTP Host an HTTP host server domain name can be included in the HTTP header that is forwarded to the real server.

 

Rathan_FTNT_1-1638861507024.png

 

TCP forwarding and SSH.

 

TCP forwarding can be selected as the service when adding or editing a service or server mapping.

 

Rathan_FTNT_2-1638861507027.png

 

 

Add servers from firewall addresses. Enable Enable Additional SSH Option to configure a client certificate and host key validation.

 

Rathan_FTNT_3-1638861507028.png

 

 

A client certificate allows users to perform one-time user authentication to authenticate the SSH access proxy.

See ZTNA SSH access proxy example for details.

Select a certificate from the drop-down list, or create a new one.

 

Rathan_FTNT_4-1638861507031.png

 

 

Host key validation allows the ZTNA proxy to validate the SSH server using the host key before forwarding traffic to it.

 

Select the Host key field to add or create an SSH host key.

 

Rathan_FTNT_5-1638861507033.png

 

 

SAML.

 

SAML can be enabled when configuring a ZTNA server, and a SAML SSO server can be selected or created.

 

Rathan_FTNT_6-1638861507035.png

 

 

 

Rathan_FTNT_7-1638861507037.png

 

 

If the SAML SSO server does not have an authentication scheme or rule associated with it, warnings are shown.

 

Rathan_FTNT_8-1638861507040.png

 

 

Select 'Configure' in each warning to add an authentication scheme and rule.

 

Rathan_FTNT_9-1638861507041.png