- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is it possible to include a ZTNA tag inside a local-in policy?
hello everybody, I defined a ZTNA Group that includes two ZTNA Tags:
 
I know that a firewall policy can work with ZTNA Tags. But is it the same for a local-in-policy?
Looking at the documentation:
config firewall {local-in-policy | local-in-policy6} edit <policy_number> set intf <interface> set srcaddr <source_address> [source_address] ... set dstaddr <destination_address> [destination_address] ... set action {accept | deny} set service <service_name> [service_name] ... set schedule <schedule_name> set comments <string> next end
It generally talks about a destination address. But is the local-in-policy capable of understanding a ZTNA group?
I didn't find anything indicative about this. I'm working on a Fortigate 60F v7.2.11.
Thank you
Solved! Go to Solution.
- Labels:
-
FortiClient
-
FortiClient EMS
-
FortiGate
-
ZTNA
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Raffael
As per my knowledge you can't.
But depending on what you want to achieve you may transform your local-in policy to a firewall policy using a loopback address.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Raffael
As per my knowledge you can't.
But depending on what you want to achieve you may transform your local-in policy to a firewall policy using a loopback address.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ZTNA in Local-in policy ? Nope, not possible yet, but give Fortinet folks a break - they just (7.2) introduced Geo address object and ISDB (7.4.4) in Local-in policy, and already asking for ZTNA :) ...
Some day probably ...
Thanks @AEK for the mentioning.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I just want to clarify that by the example above I mean you can see how you can transform your local-in policy to a firewall policy using a loopback address, and you can then use ZTNA tag to access the FGT resource (admin UI, ssh, VPN and so).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Not possible. No config parameters available:
