Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
maxheadroom
New Contributor

ZTNA for Windows File Share on Domain-Joined Client

I am experimenting with ZTNA and FortiClient and having success except for accessing a Windows File Share in a seamless manner.  The Fortinet ZTNA documentation provides two great examples for RDP and SMB.  RDP works.  The SMB example only works on a non-domain-joined client.  I can map the drive successfully via ZTNA using FQDN and "connect using different credentials" and providing my same login credentials.  But that does not survive a reboot.  Nor does mapping by IP instead of FQDN.

 

I think Kerberos is getting in the way.  There is no direct line of sight to a DC.  I have gone down the rabbit hole of configuring a Windows KDCProxy and configuring the client to use the proxy.  This has not yet corrected the issue though I am reviewing my KDCProxy configuration.

 

If anyone could share tips to get SMB working via ZTNA is a way that is seamless to the end user, I would appreciate it.

4 REPLIES 4
Anthony_E
Community Manager
Community Manager

Hello Max,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Anthony-Fortinet Community Team.
Anthony_E
Community Manager
Community Manager

Hello Max,

 

We are still looking for someone to help you.

We will come back to you ASAP.


Regards,

Anthony-Fortinet Community Team.
Sx11
Staff
Staff
chrisW4
New Contributor III

I'm struggling with the Kerbereos  problem since months.

Fortinet support was not able to help by now.

Christoph Christian
Christoph Christian
Top Kudoed Authors