Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
miciti
Contributor

Getting started with ZTNA: firewall policy only for managed FortiClient devices

Hello everyone,

Since we did move to FortiClient EMS end of last year I do want to start diving into ZTNA now:

 

I do have a VLAN that is not connected to my windows domain server (Domain Controller, File-Server, ...). This VLAN is for third party machines and computers (robotics, PLC, IOT devices, ...)


Now there is a use case that some of our plc programmers want to work in this specific VLAN for the ease of access to the robotics but also need to access e.g. windows File-Server.

 

What is the easiest way to set it up? Basically I was thinking about creating a policy that only allows FortiClient EMS managed devices.

 

I do see the ZTNA Tags created from EMS in the FortiGate. Should I go for the "IP/MAC Based Access Control" in a "standard" FortiGate policy where I can secelt the ZTNA tags? Or do I need a full ZTNA policy?

 

uv79Z1OCCz.png

 

 

 

ZTNA policies documentation seems to often point into a kind of webserver scenario - that is not really needed here. So do I need a ZTNA server with access proxy setup?

1 Solution
ebilcari
Staff
Staff

Basically since the segments are from the internal network (On-fabric), this is the easiest way. You may need to create other ZTNA tags (not using all) and allow access only for the hosts that are compliant and don't have any security concerns reported by EMS.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.

View solution in original post

2 REPLIES 2
ebilcari
Staff
Staff

Basically since the segments are from the internal network (On-fabric), this is the easiest way. You may need to create other ZTNA tags (not using all) and allow access only for the hosts that are compliant and don't have any security concerns reported by EMS.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
miciti

@ebilcariThank you very much! I did a test with one policy and it seems to work quite well so far :)

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors