- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Forticlient EMS 7.2 and FQDN
Fortigate 7.2.9
Forticlient 7.2.4.0972
Forticlient EMS 7.2.4.983
I've gotten this to work using just the internal IP address over ZTNA for connecting to an RDP server.
I followed the steps to configure ZTNA for use with FQDN (ZTNA TCP forwarding access proxy with FQDN example | FortiGate / FortiOS 7.2.0 | Fortinet Document L...)
When I do a name resolution for my RDP server, it resolves to the VIP 10.235.0.3, as expected. Yet when I try to connect, it fails.
Is there a better document for using FQDN with ZTNA since the document is for 7.2.0 and my fortigate is 7.2.9?
- Labels:
-
FortiClient EMS
-
ZTNA
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello @chedstrom,
you can check following guide that shows the config related top FQDN-based ZTNA TCP forwarding proxy.
Regards
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
7.2 and later no longer modifies the host files so why would I go backwards?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
When you ping the related FQDN from FGT does it resolve it to its IP address?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The VIP or the inside IP? See my original post.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I mean from the FortiGate, not from the client.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Why would the public IP need to accept ICMP?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I mean DNS resolution. In case you use FQDN in your ZTNA server config, can your FG resolve the FQDN of your back-end server to its correct IP address?
Created on ‎08-23-2024 11:14 AM Edited on ‎08-23-2024 11:44 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes the server behind the Fortigate can be resolved by its FQDN and responds to ICMP from the Fortigate.
