FortiGate running 7.4.2
This is probably going to sound weird but I setup my first ZTNA ssh proxy and it works. However, in the firewall policy I have defined a few tags that can use the policy. The tags are different ActiveDirectory Groups our EMS has picked up.
So I have a tag for the Operations group (which I am a member of) and a tag for the QA group which I am not a member of. Then we have a tag called EXAMPLE which is our entire AD domain. All users in our domain are a member of this tag.
When the firewall policy only has the tags Operations and QA with a match ANY I get a deny for this policy. If I add the tag EXAMPLE to the policy I can use it.
My question is is there a diagnose command I can run to see how the FortiGate is going through the policy and trying to determine if a users tag is a match or not?
Hello,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Hello,
To trace ZTNA posture tags in a policy, follow these steps:
Regards,
User | Count |
---|---|
2552 | |
1356 | |
795 | |
646 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.