Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Jesse_D_Ebel
Staff
Staff

Need to differentiate AWS API calls based off ZTNA trusted users vs standard users

A customer looking to secure API calls to their Control server between standard "Trusted Users" vs "Super Trusted Users".  "Super Trusted Users" will only connect from their On-prem locations.  They like the idea of ZTNA access proxy and FortiClient Posture checks/policy to allow "Super Trusted Users" to have the ability to make any API call to the control server and limit the API calls from the standard "Trusted users".

 

If we place a FortiGate VM in their AWS cloud before the Control Server, can the ZTNA Access Proxy differentiate API calls (via URL or something else) or will they need to use a FortiWeb API Gateway or spin up another API Gateway for each level of access?

 

 

 

#ZTNA #EMS #FortiWeb

1 REPLY 1
gfleming
Staff
Staff

Not famliar with AWS and APIs but can you restrict API access directly in FlightControl based on things like source IP?

Cheers,
Graham
Labels
Top Kudoed Authors