Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
AlbertMin
New Contributor II

Fortigate Policy with ZTNA Tag

Hello,

 

we have Fortigate v7.2.4 and Forti EMS v7.0.7

In Forti EMS I have created a zero trust tagging rule. To test, simply whether the file c:\temp\test.txt exists.
I can use this rule in a policy on the Fortigate (IP/MAC Based Access Control).
We use this for SSL VPN dial-ins.
For example, a VPN-Client should only be able to ping an internal server if the file c:\temp\test.txt exists on the VPN-Client. This also works perfectly.
But we're going in the other direction. A VPN -Client should only be able to be pinged from an internal server if the file c:\temp\test.txt exists on the VPN-Client.
That does not work. Is that even possible?

 

Thank you

Martin

1 REPLY 1
funkylicious
SuperUser
SuperUser

Hi,
So basically, a device would be tag-ed if that file exists.

You could try and use that tag as destination in the rule, just a thought.

"jack of all trades, master of none"
"jack of all trades, master of none"
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors