Description |
This article describes the behavior of the email approval feature when configuring FortiPAM with multiple access proxies. |
Scope | FortiPAM v1.5.x, FortiPAM v1.6.x. |
Solution |
When configuring FortiPAM with multiple access proxies, APPROVAL_LINK in the email template will always refer to the first access proxy VIP. For example, configure the multiple access proxy as follows: ZTNA-based FortiPAM access control
Configure the email template and email approval feature in FortiPAM, follow the document below: Approval email template When approver (from a non-ZTNA machine) selects the 'Approve' button in the email, it will redirect to the first access proxy external IP and getting denied. This is because the 'Approve' button, which links to the variable %%APPROVAL_LINK%% in the email template, will by default select the first access proxy VIP’s external IP configured.
To change the selection of access proxy VIP, configure the proxy FQDN:
config web-proxy global
The FQDN in the above example can be linked to any of the access proxy VIP’s external IP addresses that are needed with a proper DNS setup.
The behavior for IP selection for the APPROVAL_LINK variables is as follows:
Public IP and private IP definitions follow the standard RFC 1918 and 1166. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.