Description | This article describes a solution to fix the issue where ZTNA is not working in external/off-net clients, but working in internal/on-net endpoints. |
Scope | FortiGate, FortiClient EMS. |
Solution |
In this scenario, the ZTNA tags are synchronized in FortiClient EMS and FortiClient endpoint but fail to synchronize in FortiGate.
On FortiClient EMS, it shows that both the internal and external endpoints are tagged by ZTNA as 'Windows'.
On the FortiClient endpoint, the external client is tagged by ZTNA as 'Windows'.
On FortiGate, the ZTNA tags are not synchronized. It only shows the internal endpoint 10.230.3.17 tagged by ZTNA.
To resolve the issue, activate 'Share all FortiClients' in FortiClient EMS under Administration -> Fabric Devices so the FortiGate will receive ZTNA host tags for all endpoints, regardless of their gateway.
On FortiClient EMS, go to Administration -> Fabric Devices and select the Edit icon.
On FortiClient Endpoint Sharing, select 'Share all FortiClients' and select Update to save.
On the external endpoint, on FortiClient -> Zero Trust Telemetry, disconnect from FortiClient EMS, then reconnect to EMS. Upon syncing, the ZTNA tag for both the internal 10.230.3.17 and external endpoint 10.47.17.179 should synchronized in FortiGate.
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.