Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
MayurAtTTI
New Contributor

Connection Timeout Issues with REST API and ApacheMQ Broker Service under ZTNA Policy

Dear Support Team,

I hope this message finds you well.

I am a Java developer working remotely and have recently encountered connectivity issues with our internal servers following the implementation of the Zero Trust Network Access (ZTNA) policy. Previously, I was able to connect to our servers using a VPN without any problems. However, since the transition to ZTNA, I am consistently facing connection timeout errors.

2 REPLIES 2
Anthony_E
Community Manager
Community Manager

Hello,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Anthony-Fortinet Community Team.
Sx11
Staff
Staff

Hello MayurAtTTI,

 

is the ZTNA configuration a HTTP access proxy or TCP forwarding proxy?

 

To investigate the issue you can enable following debugs in FGT CLI:

 

dia de reset

diagnose wad debug enable category all

diagnose wad debug enable level verbose

diagnose debug enable

 

 

Recreate the issue and after finishing enter the following to display ZTNA logs:

 

execute log filter category 0

execute log filter field subtype ztna

execute log display

 

This will give you an idea if there are device posture changes that would results in Policy violations.

Log&Report>ZTNA traffic should also provide you information about this.

 

Alternatively you can try to customize session ttl.

This can be used if stale TCP sessions need to be timed out faster, or should stay alive longer as certain software might need a longer session-ttl to keep functioning.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Customizing-Session-TTL-in-FortiOS/ta-p/19...

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configuring-session-TTL-timers-for-particu...

 

Regards

 

sx11
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors