FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
pmeet
Staff
Staff
Article Id 294712
Description This article describes how to implement ZTNA TCP forwarding for public-facing servers.
Scope FortiOS , FortiClient, Forticlient EMS
Solution
  1. First, create a ZTNA destination on the EMS and apply the ZTNA destination profile to the correct Endpoint policy.

 

ZTNA-1.PNG

 

ZTNA-2.PNG

 

In this example, ZTNA TCP-forwarding will be applied to www.youtube.com.

 

ZTNA-3.PNG

 

  1. Confirm if the new ZTNA destination is appearing for the user on the FortiClient:

 

ZTNA-4.PNG

 

ZTNA-9.PNG

 

The IP 10.235.0.1 is what will be provided by the FortiClient. This ensures that TCP forwarding is applied as expected on the endpoint.

 

  1. Now, create a ZTNA server and Proxy policy on the FortiGate to authenticate traffic.

 

ZTNA-5.PNG

 

ZTNA-6.PNG

 

Create a FQDN address object on the FortiGate with www.youtube.com and use it in the Server field as above:

 

ZTNA-7.PNG

 

ZTNA tags can be applied to the policy as necessary as well:

 

ZTNA-10.PNG

 

Traffic will now be allowed by the proxy policy, and ZTNA will be applied when the user accesses YouTube on the endpoint.