Hi. I've been a user of SSL-VPN until it was removed from the latest firmware.
I've clients using ubuntu linux variants and have problems setting IPSEC for them via strong swan.
Any advice if switching to ZTNA would solve most issues?
I presume I can install this "ZTNA Forti s/w" on linux?
Would just getting a ZTNA licence be enough? What about the configuration of EMS. How is it done?
Another question I have is I've 2 Fortinet.
Fortinet 1 has a public uplink and serves some services in the clear.
It has a port that is attached to Fortinet 2 that turns on and off.
Fortinet 2 serves services in a locked-down environment.
Would I be able to have ZTNA running on Fortinet2 having Fortinet1 as an uplink?
End state is my users be able to connect to Fortinet1 and Fortinet2 one at a time to use services in both networks.
Hi Alan
For strongSwan under Linux check this tech tip.
For ZTNA configuration (EMS), if you are not familiar with EMS integration then you better call a Fortinet partner, as it requires some skills.
Typical case is to configure ZTNA gateway on the front-end firewall. Or I may not understand well what are you looking for.
Just wondering if you know if 2FA works on the strong swan?
2FA is supported since strongSwan supports at least ssl certificate.
If you mean OTP token, then in theory any client supports 2FA, either by RADIUS challenge or by password+token concatenation.
I mean forti-tokens to be exact.
Sorry for the confusion.
I didn't test it but I here is my thought
User | Count |
---|---|
2534 | |
1351 | |
795 | |
641 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.