Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Akmostafa
New Contributor III

ZTNA in windows domain infrastructure and client-to-domain-controller traffic

Hello Folks,

 

windows environment seem to be somehow complex to me when dealing with ZTNA, especially when knowing that some transactions need line-of-side connections between clients and the DC, many ports being used on both TCP and UDP.

 

In my scenario, I have configured a ZTNA server to the LDAP, included all ports required. UDP seem to work, cause I have tried to resolve names from the client side. However, when it comes to the user login (with a new username that is not cached on the client machine or after resetting a domain user`s password), things not working.

 

I have seen this kb about the need for a KDC proxy for accessing shared folders. Do I need a KDC also to allow users to login to their machines when they are at home (especially after a password change?)

 

ZTNA access proxy with KDC to access shared drives | FortiGate / FortiOS 7.4.1 | Fortinet Document L...

 

Secondly, for the sake of troubleshooting, sometimes I needed to analyze packets from the fG to the backend servers while preserving the client`s IP address. I have found the below document but it did not help because it talks about editing a proxy policy, while in 7.4, ztna configurations are under ordinary firewall policy , even when I tried to disable the NAT, I Stil cannot see traffic between the firewall and backend server when performing a sniffer (filtered by client IP address and backend server ip address)

 

Using the IP pool or client IP address in a ZTNA connection to backend servers | FortiGate / FortiOS...

7 REPLIES 7
Jean-Philippe_P
Moderator
Moderator

Hello Akmostafa, 

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible. 

 

Thanks, 

Regards,

Jean-Philippe - Fortinet Community Team
Anthony_E
Community Manager
Community Manager

Hello,

We are still looking for someone to help you.

We will come back to you ASAP.


Thanks,

Anthony-Fortinet Community Team.
Anthony_E
Community Manager
Community Manager

Hello,

 

Sorry for the delay, we are still looking for someone to help.

 

Regards,

Anthony-Fortinet Community Team.
Anthony_E
Community Manager
Community Manager

Hello,

 

May I invite you to open a ticket from our support portal?: https://support.fortinet.com/welcome/

 

Regards,

Anthony-Fortinet Community Team.
Akmostafa
New Contributor III

Already done that.

But it seems there is lack of documentation regarding this topic.

Anthony_E
Community Manager
Community Manager

Do you maybe have a solution to share here?

 

Regards,

Anthony-Fortinet Community Team.
funkylicious
SuperUser
SuperUser

hi,

in 7.4 you can configure the ZTNA rules under Explicit Proxy/Proxy Policy as per this instead of classic firewall rules.

"jack of all trades, master of none"
"jack of all trades, master of none"
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors