FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
akushwaha
Staff
Staff
Article Id 326724
Description

This article describe how to check the resolved addresses of EMS endpoint in FortiGate.

Scope FortiGate, FortiEMS.
Solution

After connecting the endpoint to EMS, FortiGate receives the tag information and the resolved endpoint address of connected devices.

However, if the device is not directly connected to the FortiGate, it will not show the information. 

 

The following screenshot shows the TEST tag, which the endpoint gets after connecting to EMS.

 

ztna.jpg

 

By default, FortiGate will not show the address information of all endpoint addresses in ZTNA Tags on FortiGate.

 

image (5).jpg

 

In order to check the endpoint addresses, follow the steps below.

 

Verify the IP address of the user machine which is connected with the EMS server.

 

image (3).png

 

Open the EMS server and navigate to Administration -> Fabric Devices.

Select the FortiGate, edit it and change the settings to 'Share all FortiClients' under FortiClient Endpoint Sharing. By default, this is set to 'Only share FortiClients connected to this fabric device'.

 

image (6).png

 

image (7).png

 

image (8).png

 

Once it is updated, resolved addresses can be viewed in FortiGate under ZTNA -> Security Posture Tags -> Resolved addresses.

 

image (9).png

 

 

image (10).jpg

 

Contributors