Created on
04-22-2025
12:53 AM
Edited on
06-25-2025
05:08 AM
By
Jean-Philippe_P
Description | This article describes how to create a ZTNA destination rule and assign it to a profile in FortiSASE, where this destination rule needs to be pushed to a specific group of users only. |
Scope | FortiSASE, FortiGate. |
Solution |
When configuring ZTNA access proxy with the TCP Forwarding type, a ZTNA destination rule is required. In some cases, these destination rules must be delivered only to certain users connected through FortiSASE.
FortiSASE allows the application of destination rules based on specific profiles. This enables targeting destination rules to particular user groups, with each profile determining the appropriate destination rule and corresponding application gateway to utilize.
As shown in the screenshot below, configure the real IP address of the Server/Application and select the application gateway needed.
After the above configuration. FortiSASE should push the destination rules to FortiClient that belongs to this profile 'DomainJoinedUsers' only. While users who belong to other profiles will not contain this destination Rule. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.