Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
seuledr6616
New Contributor

Basic ZTNA Design / Functionality Questions - ZTNA Server

Hello all!

 

I have some questions regarding some basics of the Fortinet ZTNA setup. I did go through the ZTNA and FortiEMS training but just wanted some things clarified if possible.

 

1st Dumb Question - Is the ZTNA Server just one of my Fortigate Firewalls? (It's not another physical box/server I have to setup right?) It seems like if I have two locations, each Fortigate could be a ZTNA server for access to the resources that are located there. Both would have to be joined via the Fabric connectors and one of those would have to serve as the "Fabric Root".

 

If the above is true, when I'm setting up my ZTNA Server on one of the Fortigates, for the external IP, can I just choose any IP that's associated with my assigned block, and would I then connect via that IP address for access resources externally? (Let's say I have 123.123.123.1-50 for my external IPs, can I just set that external IP to 123.

123.123.5, then if I setup rules to access SMB let's say, when I map a network drive from home, would I just be utilizing that ZTNA server IP I chose (the .5), or am I able to use existing assigned external IPs for resources and the external ZTNA server IP has nothing to do with those?

 

I apologize for some of these basic questions, but the documentation and training didn't cover some of this very well (it just says "Setup your ZTNA server and assign these things"). The ZTNA server piece I'm a little confused about.

1 Solution
Sx11
Staff
Staff

Hi seuledr6616,

 

the ZTNA Server is configuration defines your access proxy GW (FortiGate) and additionally it contains the service/server mappings.

So it is made of 2 elements.

1.Access proxy VIP - Where clients will make the HTTPS connection.(fortigate is the access proxy)

2.Service/server mappings - this is a host matching rule so FGT will redirect clients to your internal protected resource/server.

 

To better understand this we have a Basic config for ZTNA guide which elaborates with an example and explanation:

https://docs.fortinet.com/document/fortigate/7.2.8/administration-guide/194961/basic-ztna-configurat...

 

 

Additionally if you are interested in SMB you can check the following:

In this example, RDP (Remote Desktop Protocol) and SMB (Server Message Block) protocol access are configured to one server, and SSH access to the other server. 

https://docs.fortinet.com/document/fortigate/7.2.8/administration-guide/101256/ztna-tcp-forwarding-a...

 

Regards

sx11

View solution in original post

1 REPLY 1
Sx11
Staff
Staff

Hi seuledr6616,

 

the ZTNA Server is configuration defines your access proxy GW (FortiGate) and additionally it contains the service/server mappings.

So it is made of 2 elements.

1.Access proxy VIP - Where clients will make the HTTPS connection.(fortigate is the access proxy)

2.Service/server mappings - this is a host matching rule so FGT will redirect clients to your internal protected resource/server.

 

To better understand this we have a Basic config for ZTNA guide which elaborates with an example and explanation:

https://docs.fortinet.com/document/fortigate/7.2.8/administration-guide/194961/basic-ztna-configurat...

 

 

Additionally if you are interested in SMB you can check the following:

In this example, RDP (Remote Desktop Protocol) and SMB (Server Message Block) protocol access are configured to one server, and SSH access to the other server. 

https://docs.fortinet.com/document/fortigate/7.2.8/administration-guide/101256/ztna-tcp-forwarding-a...

 

Regards

sx11
Labels
Top Kudoed Authors