Hi ZTNA admins
Regarding EMS georedundancy HA deployment, on each site there is one EMS, one edge FGT, and each has its public IP. The clients are registered with ztna.domain.com pointing to the first site's public IP.
My question is, what is the best way to have a redundant deployment that makes switching ZTNA app gateway as transparent as possible to the user.
My first though is to use FortiADC's GSLB, so the DNS directs to the available ZTNA gateway. However it seems for me an excessive solution for a small problem. So I think that some simpler solutions should exist.
Any idea will be welcome.
Hello Abdelkrim,
I hope you are doing well :)!!!
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Hello Anthony
Hope you are doing fine too.
Thanks for your support!
As usual, it is a pleasure if we can help you.
I found this answer with our documentations:
To achieve a redundant deployment for ZTNA Application Gateway with minimal user disruption, you can consider the following approach:
DNS Configuration:
ztna.domain.com to the primary site's public IP.FortiADC GSLB:
FortiGate Configuration:
Monitoring and Alerts:
Testing and Validation:
By using a combination of DNS failover and FortiGate's capabilities, you can achieve a redundant deployment that is both cost-effective and efficient for a smaller setup.
Is that helping?
Regards,
Thanks for your feedback, Anthony.
This is indeed one of the possible solutions.
Any other suggestions are welcome.
| User | Count | 
|---|---|
| 2727 | |
| 1416 | |
| 810 | |
| 738 | |
| 455 | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.