Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
nopethanks
New Contributor II

Where to start with ZTNA?

Hi there,

 

I've got a FortiGate running 7.2.9 and FortiClient EMS server running on 7.4.1 but I'm not quite sure where to start getting ZTNA up and running. We use Okta for our IdP and I'm presuming that'll be what manages the role based access control but I was hoping there was some guide available to walk you through getting everything working together.

 

Everything I've found so far has been for previous versions of FortiClient EMS which requires Active Directory (which we don't have.) If anyone can point me in the right direction, I would REALLY appreciate it!

 

Thanks!

3 REPLIES 3
rahul_p1
Staff
Staff

Hi, Please refer to the article for understanding and configuration of ZTNA :- https://docs.fortinet.com/document/fortigate/7.0.0/new-features/194961/basic-ztna-configuration

Hemin88
New Contributor III

Hi @nopethanks 
Best way to start from this video:
https://video.fortinet.com/latest/getting-started-with-ztna

then:

Fortinet Document Library | Home

 

and Kbs 


 

 

IP Network Engineer
IP Network Engineer
Hatibi
Staff
Staff

Since you intend to use ZTNA with SAML (okta as IDP) you can refer to these links for this type of scenario:

 

The examples use FortiAuthenticator as IDP. That configuration you will need to adapt to Okta.

This other doc might give an idea for Okta configuration as IDP in FortiGate: https://docs.fortinet.com/document/fortigate/7.6.0/administration-guide/499536/ssl-vpn-with-okta-as-...

 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors