- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Source address in ZTNA proxy policy
Hi EMS/FGT admins
When creating ZTNA proxy rule (in Policy & Object > Proxy Policy) for clients that are off-fabric, is there anything valid that we can put in "Source" field other than "all"?
Trying to put the public source address of the client, or even the client's private source address behind its router, but nothing seem to match, only "all" works. It seems srcaddr in ZTNA proxy rules means something different than in standard rules, but can't find what.
Any idea?
- Labels:
-
FortiGate
-
Proxy policy
-
ZTNA
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
Can you share the snapshot of the proxy policy setup for better clarity
Fortinet Certified Expert (FCX) | #NSE8-003459
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
setting up private IP should work as in the wad debug you will see the traffic coming with the private PC ip
Fortinet Certified Expert (FCX) | #NSE8-003459
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Joshi
Thanks for your response.
Here is the screenshot:
On the tech tip you shared, they are also using "all" as source address in the ZTNA rule.
