Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
eleland
New Contributor

ZTNA IPs not assigned to Users

Hello there,
maybe some of you already experienced this issue and help me out.

We have a FortiGate on Version 7.4.8 and want to use ZTNA Tags trough SSL-VPN to allow access to specific ressources.
The Tags get assigned to the endpoints and under GUI Policy&Objects -> ZTNA -> Tags the endpoint is listed under the tag with the correct SSL-VPN Tunnel IP, but using "diag firewall dynamic list" the IP is not listed anywhere.

This of course leads to the User not using the right policies.

diagnose test application fcnacd 2 and diagnose test application fcnacd 5 do not change anything, diagnose endpoint fctems test-connectivity is fine as well.

I already rebuilt the connector and we just updated the EMS to 7.4.4 (It did not work in 7.4.3 as well).

I don't know what else to try, the support is looking at it as well but could not find anything yet.

Any help would be appreciated!

2 REPLIES 2
funkylicious
SuperUser
SuperUser

hi,

after you connect to SSL-VPN and get an IP, do you have the rules in place to access EMS on port TCP/8013 ( preferably without ZTNA tags in the fw rule for this ) to ensure that the endpoint exchanges all the info with EMS and EMS with FGT ?

 

L.E. let me clarify what i mean

if you have a full-tunnel SSL-VPN , you would need to configure classic firewall rules ( no ZTNA tags ) to ensure that DNS traffic ( to resolve EMS address ) and TCP/8013 towards the EMS ( either a public IP or private IP ) are in place.

something similar is described for macOS but the same principle should apply to Windows also - https://community.fortinet.com/t5/FortiGate/Technical-Tip-ZTNA-not-working-with-SSL-VPN-on-macOS-dev... -

"jack of all trades, master of none"
"jack of all trades, master of none"
Curtava
New Contributor

Does the issue happen with all endpoints or just certain SSL-VPN connections?

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors