Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
AEK
SuperUser
SuperUser

Auto-imported ZTNA gateway IP

Hi EMS admins

FortiEMS 7.4.4, FortiOS 7.4.8.

Knowing that, starting from FortiOS 7.4.x, ZTNA gateway info and 2TNA apps are imported by EMS from FGT automatically.

The issue comes when my FGT is behind NAT, so my FGT WAN interface has a private IP.

So when I configure ZTNA server on my FGT it must have the private IP of the interface, like shown below.

 

ztna_priv.png

 

The when imported automatically bu EMS, the gateway IP is the same, and it is pushed to clients as is.

So when off-fabric client's want to access a ZTNA app they us this private IP, which is not possible because they are off-fabric.

(In scenarios where the public IP is on the WAN interface all works fine).

To resolve my issue I had to manually recreate the ZTNA gateway and all ZTNA apps on EMS, which is lot of work to do just because of this IP address, because imported gateway and apps are not editable on EMS.

Do you know any simpler way to resolve it? Like is there a way to keep the auto imported info and just replace the gateway IP by the public one?

AEK
AEK
4 REPLIES 4
Stephen_G
Moderator
Moderator

Hi AEK,

 

Thanks for your post - we'll look to get you an answer as soon as we can.

 

If anyone reading this has any ideas, feel free to contribute!

Stephen - Fortinet Community Team
AEK

Hi Stephen

Thanks for your support!

AEK
AEK
funkylicious
SuperUser
SuperUser

Hi AEK,

an idea would be to create 2 different ZTNA servers on the FGT ( with private and public IP as external ) and in EMS assign each one to a specific ZTNA profile ( having one for each situation, on- and off- ) depending if the client would be on-fabric or off-fabric.

"jack of all trades, master of none"
"jack of all trades, master of none"
AEK

Hi funkylicious

Yes I think this workaround should work. However at that point if I have choice I'd still prefer the manual method.

AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors