Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
chedstrom
New Contributor II

Forticlient EMS 7.2

We are in the process of doing a basic Forticlient EMS setup. I've been going through all documentation and searching for answers to the last part of the puzzle. 

 

Our setup: 

Forticlient EMS on Windows Server

Fabric is configured on FortiGate and syncing tags correctly (although not currently used)

We have setup a VIP to permit the telemetry port 8013 through to the EMS server.

 

We have configured one ZTNA connection for an RDP server. We are currently using default 443 for the ZTNA connection to the inside device on port 3389 just for testing.

 

The client device is connecting to the EMS server and is receiving the ZTNA destination correctly. 

 

We have configured a ZTNA Server to allow the TCP traffic from external ip on port 443 to the internal ip on port 3389. 

 

We have also created a Firewall Policy for ZTNA to allow the traffic to the ZTNA Server.

 

But at this point when we try to connect to the RDP server on our test machine, we never see traffic hitting the ZTNA firewall policy. What I don't understand is how does the Forticlient on the test machine knows to route or intercept that traffic. I feel like I missed a large piece of the puzzle even after reading ZTNA documentation in the knowledgebase. Can anyone point me in the right direction?

 

Note: The RDP connection is only using IP addresses, and we will deal with DNS configurations later. 

1 Solution
chedstrom
New Contributor II

The end results was a broken Security Fabric connector.

Despite running the "diagnose endpoint fctems test-connectivity" showing the connector was OK, we had to reconnect it to fix. 

Just putting it out there for anyone else. 

View solution in original post

2 REPLIES 2
AEK
SuperUser
SuperUser

What I don't understand is how does the Forticlient on the test machine knows to route or intercept that traffic.

-> Simply your FortiClient acts as a proxy for the defined ZTNA destinations.

Try check the following:

  • Client is receiving the right tags
  • Client is receiving the right ZTNA destination info
  • Your ZTNA server config / service mapping on FGT should use TCP forwarding service type instead of HTTP/HTTPS
  • Your firewall rule type should be ZTNA, not standard

The below tech tip should help.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Connect-to-Remote-Desktop-Server-RDS-farm-...

 

AEK
AEK
chedstrom
New Contributor II

The end results was a broken Security Fabric connector.

Despite running the "diagnose endpoint fctems test-connectivity" showing the connector was OK, we had to reconnect it to fix. 

Just putting it out there for anyone else. 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors