FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
pachavez
Staff & Editor
Staff & Editor
Article Id 325571
Description This article describes a solution to fix the issue where ZTNA is not working in external/off-net clients, but working in internal/on-net endpoints.
Scope FortiGate, FortiClient EMS.
Solution

In this scenario, the ZTNA tags are synchronized in FortiClient EMS and FortiClient endpoint but fail to synchronize in FortiGate.

 

ems diagram 2.png

 

  1. Check the FortiClient EMS Connector status. On FortiGate, navigate to Security Fabric -> Fabric Connectors -> FortiClient EMS. 

 

EMS Connector.PNG

 

  1. Check the status of FortiGate in FortiClient EMS. On FortiClient EMS, navigate to Administration -> Fabric Devices. FortiGate should show authorized. 

 

FortiClient EMS edited.png

 

  1. Check the ZTNA tags in FortiClient EMS, FortiClient endpoint, and FortiGate.

 

On FortiClient EMS, it shows that both the internal and external endpoints are tagged by ZTNA as 'Windows'.

 

FortiClient EMS ztna 3.PNG

 

On the FortiClient endpoint, the external client is tagged by ZTNA as 'Windows'.

 

forticlient endpoint.PNG

 

On FortiGate, the ZTNA tags are not synchronized. It only shows the internal endpoint 10.230.3.17 tagged by ZTNA.

 

fortigate ztna.png

 

fortigate ztna 2.PNG

 

To resolve the issue, activate 'Share all FortiClients' in FortiClient EMS under Administration -> Fabric Devices so the FortiGate will receive ZTNA host tags for all endpoints, regardless of their gateway.

 

On FortiClient EMS, go to Administration -> Fabric Devices and select the Edit icon.

 

EMS Fabric Devices edited.png

 

On FortiClient Endpoint Sharing, select 'Share all FortiClients' and select Update to save.

 

share all forticlients.PNG

 

On the external endpoint, on FortiClient -> Zero Trust Telemetry, disconnect from FortiClient EMS, then reconnect to EMS.

Upon syncing, the ZTNA tag for both the internal 10.230.3.17 and external endpoint 10.47.17.179 should synchronized in FortiGate.

 

fortigate ztna after activating share all forticlient.PNG

 

Contributors