Created on
03-28-2022
09:55 PM
Edited on
02-24-2025
06:41 AM
By
Jean-Philippe_P
Description | This article describes how to configure a ZTNA Rule for remote access to file shares (SMB). |
Scope | FortiGate v7.0.4, FortiClient v7.0.3. |
Solution |
Starting with FortiOS v7.0.4 and FortiClient v7.0.3, it is possible to leverage ZTNA TCP Forwarding Access Proxy rules to connect to a file share remotely without the need for a VPN connection.
Reviewing the following document may be helpful to better understand the ZTNA components. Zero Trust Network Access introduction
Configuration Steps.
The same steps can be used from other TCP Forwarding configuration examples as per the administration guide link below. The only difference is that the port used for SMB is 445.
ZTNA TCP forwarding access proxy example
Note. Starting with FortiClient EMS v7.0.3, ZTNA Connection Rules can also be created via GUI rather than only via XML files.
It is common to map network drives using the file server name. This can also be done starting with FortiClient v7.0.3, which supports FQDN-based ZTNA TCP forwarding services as per the documentation below.
FQDN-based ZTNA TCP forwarding services
ZTNA TCP forwarding access proxy with FQDN example
File share can be accessed directly if the full path is known or it can be mapped to a network drive by browsing the file server tree.
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.