Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
AEK
SuperUser
SuperUser

Source address in ZTNA proxy policy

Hi EMS/FGT admins

When creating ZTNA proxy rule (in Policy & Object > Proxy Policy) for clients that are off-fabric, is there anything valid that we can put in "Source" field other than "all"?

Trying to put the public source address of the client, or even the client's private source address behind its router, but nothing seem to match, only "all" works. It seems srcaddr in ZTNA proxy rules means something different than in standard rules, but can't find what.

Any idea?

AEK
AEK
3 REPLIES 3
sjoshi
Staff
Staff

Hi,

 

Can you share the snapshot of the proxy policy setup for better clarity

Let us know if this helps.
Salon Raj Joshi
sjoshi
Staff
Staff

setting up private IP should work as in the wad debug you will see the traffic coming with the private PC ip

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Sample-configuration-Proxy-ZTNA/ta-p/24205...

Let us know if this helps.
Salon Raj Joshi
AEK
SuperUser
SuperUser

Hi Joshi

Thanks for your response.

Here is the screenshot:

ztan_proxy_rule.png

 

On the tech tip you shared, they are also using "all" as source address in the ZTNA rule.

AEK
AEK
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors