Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
systemgeek
Contributor II

ZTNA Proxy Policy config needs for tcp-forwarding

In all the examples I have seen on how to create a tcp-forwarding proxy policy for ZTNA I always see the following config parts:

config firewall access-proxy

config firewall proxy-policy
 
Some times they do include:
config firewall policy
 
In my testing I have noticed that a firewall policy config is not required.  I am sure there is a good reason for having a firewall policy regardless.  Can some one tell me what benefits you can get from including the firewall policy?
2 REPLIES 2
AEK
SuperUser
SuperUser

For internal-to-internal traffic I use firewall rules only (regular rule with ZTNA tags).

For external-to-internal traffic (ZTNA server config) I use proxy rules only (type ZTNA).

And it works always fine.

AEK
AEK
vokelmo4
New Contributor

Do you run a terminal services gateway. I was able to get this working without too much issue over 443. The main thing i found is I had to use the hostname rather than IP for the mapped server and also needed to make sure the FortiGate was using internal DNS servers for its resolvers to resolve the hostname internally.

omegle xender
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors