Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
zoriax
Contributor

ZTNA Tags IP/MAC are empty

Hello everyone,

 

I'm really suggering with ZTNA :( :) 

 

I tried to get IP/MAC informations inside my ZTNA tags on FortiGate. I configured corretly EMS / Forticlient and Fortigate. My tags are sync successfully but the are emtpy 

 

On my fortiGate, my device is correctly registred : 

zoriax_1-1648199260879.png

My tag is correctly added : 

zoriax_2-1648199290686.png

But when I looked inside it on my FortiGate, the tag is definitevly empty : 

zoriax_3-1648199331895.png

I don't know what I can do to correctly sync device information with my fortigate. I'm sure it's simple but I can't find how.

 

I really need your help ! 

 

Thanks

 

 

 

15 REPLIES 15
zoriax
Contributor

I tried with IPSec VPN tunnel in my case. Effectively it seems to work with SSL but why not with IPSec ?

 

Thanks

amouawad
Staff
Staff

For the sake of complete testing, the above test was done on a FCT that was On-Net/On-Fabric. I've tested with the device Off-Net/Off-Fabric and can confirm that the IP addresses still get updated correctly.

 

2022-03-29_23-49.pngFCT Off-Net, connecting via SSLVPNFCT Off-Net, connecting via SSLVPN

zoriax
Contributor

Anyone has a solution to sync IP/MAC with and IPSec VPN ?

Ronny
New Contributor

We have also an issue with Tags in SSL VPN or IPSec VPN. Is there a solution?

zoriax

Hi @Ronny 

 

It's a bit better with last version of EMS (7.0.4).

IvanCRO
New Contributor

Hi, I have same issue. We have multi-vdom fortigate. In DMZ vdom I put my EMS and integrated it with AD and Fortigate. Everything seems fine. ZTNA tags are replicated to fortigate. In Business vdom when looked in ZTNA tags when hoovering over ZTNA TAG "X" I can see that it matches endpoints. But in resolved addresses I can't see anything.

Also, when I go in firewall policy rule, in IP/MAC based I can see those addresses as resolved, very strange. 

Same setup in DMZ vdom and I can see matched endpoints, cant see resolved addresses but in firewall policy IP/MAC based I don't see any of those matched endpoints. 

In DMZ we have configured SSL VPN, same problem as these one above. 

All firewall policies from DMZ vdom to Business VDOM in which are ADs allow all traffic from EMS to ADs.

I don't know what to do next, I tried everything that found on Internet.

Also I found few more things that doesn't make sense in EMS, but step-by-step.Business policyBusiness policyBusiness ZTNA1Business ZTNA1Business ZTNA2Business ZTNA2DMZ firewall policyDMZ firewall policyDMZ ZTNA1DMZ ZTNA1DMZ ZTNA2DMZ ZTNA2

Labels
Top Kudoed Authors