In all the examples I have seen on how to create a tcp-forwarding proxy policy for ZTNA I always see the following config parts:
config firewall access-proxy
For internal-to-internal traffic I use firewall rules only (regular rule with ZTNA tags).
For external-to-internal traffic (ZTNA server config) I use proxy rules only (type ZTNA).
And it works always fine.
Do you run a terminal services gateway. I was able to get this working without too much issue over 443. The main thing i found is I had to use the hostname rather than IP for the mapped server and also needed to make sure the FortiGate was using internal DNS servers for its resolvers to resolve the hostname internally.
User | Count |
---|---|
2572 | |
1365 | |
796 | |
654 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.