Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
alansims
New Contributor

Replacing SSL-VPN with ZTNA?

Hi. I've been a user of SSL-VPN until it was removed from the latest firmware.

I've clients using ubuntu linux variants and have problems setting IPSEC for them via strong swan. 

Any advice if switching to ZTNA would solve most issues?

I presume I can install this "ZTNA Forti s/w" on linux?

Would just getting a ZTNA licence be enough? What about the configuration of EMS. How is it done?

 

Another question I have is I've 2 Fortinet. 

Fortinet 1 has a public uplink and serves some services in the clear.

It has a port that is attached to Fortinet 2 that turns on and off.

Fortinet 2 serves services in a locked-down environment. 

Would I be able to have ZTNA running on Fortinet2 having Fortinet1 as an uplink?

End state is my users be able to connect to Fortinet1 and Fortinet2 one at a time to use services in both networks.

5 REPLIES 5
AEK
SuperUser
SuperUser

Hi Alan

 

For strongSwan under Linux check this tech tip.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-IPsec-connection-between-FortiGate-and-Ubu...

 

For ZTNA configuration (EMS), if you are not familiar with EMS integration then you better call a Fortinet partner, as it requires some skills.

 

Typical case is to configure ZTNA gateway on the front-end firewall. Or I may not understand well what are you looking for.

AEK
AEK
alansims
New Contributor

Just wondering if you know if 2FA works on the strong swan?

AEK

2FA is supported since strongSwan supports at least ssl certificate.

If you mean OTP token, then in theory any client supports 2FA, either by RADIUS challenge or by password+token concatenation.

AEK
AEK
alansims
New Contributor

I mean forti-tokens to be exact.

Sorry for the confusion.

AEK

I didn't test it but I here is my thought

  • If you have FortiAuthenticator then it should be possible
  • If you don't have FortiAuthenticator (users defined on FGT) then I don't think it is possible
AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors