| Description |
This article describes the effect of the 'Default Certificate' option in the 'ZTNA Server' configuration on traffic. This article assumes familiarity with ZTNA configuration. The following link provides a reference from v7.4.7 for ZTNA deployment: Zero Trust Network Access introduction |
| Scope | FortiGate, ZTNA. |
| Solution |
When configuring a new ZTNA Server on the FortiGate (for both TCP-Forwarding and HTTPS access proxies), one of the mandatory options is to set a Default Certificate. This certificate is presented to the user when connecting to the FortiGate as a ZTNA proxy gateway:
While it is possible to use the Fortinet_Factory certificate for this purpose, it is recommended to use a proper, trusted certificate or issues can occur.
Problem: If the certificate assigned to this ZTNA server does not include the IP/FQDN used to access the ZTNA gateway as a Common Name (CN) and/or Subject Alternative Name (SAN) then users may run into warnings when attempting to connect to the service. For example, web browsers will show certificate errors when accessing a ZTNA HTTPS Access Proxy on the FortiGate, whereas FortiClient may show certificate errors when acting as a TCP Forward Access Proxy (depending on the version and the underlying configuration. The first recommendation is to obtain a certificate that is issued by a trusted Certificate Authority (e.g., GoDaddy, DigiCert, Let's Encrypt, etc.) and also has CN/SAN entries corresponding to the IPs/FQDNs used for the ZTNA gateway. This ensures that users accessing the FortiGate as a ZTNA Gateway will not encounter any TLS certificate errors/warnings, and there are a few different ways to accomplish this:
Note regarding FortiClient and EMS: When FortiClient connects to a FortiGate ZTNA Gateway that uses an invalid certificate, there are a few options for controlling its behavior:
<forticlient_configuration> <ztna> <...> <disallow_invalid_server_certificate>1</disallow_invalid_server_certificate> <warn_invalid_server_certificate>1</warn_invalid_server_certificate> <...> </ztna> </forticlient_configuration> |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.