Created on
01-17-2024
10:16 AM
Edited on
10-11-2024
08:34 AM
By
david_pereira
Description | This article describes how to implement ZTNA TCP forwarding for public-facing servers. |
Scope | FortiOS , FortiClient, Forticlient EMS |
Solution |
In this example, ZTNA TCP-forwarding will be applied to www.youtube.com.
The IP 10.235.0.1 is what will be provided by the FortiClient. This ensures that TCP forwarding is applied as expected on the endpoint.
Create a FQDN address object on the FortiGate with www.youtube.com and use it in the Server field as above:
ZTNA tags can be applied to the policy as necessary as well:
Traffic will now be allowed by the proxy policy, and ZTNA will be applied when the user accesses YouTube on the endpoint. |