Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
systemgeek
Contributor II

ZTNA posture tag trace in policy

FortiGate running 7.4.2

 

This is probably going to sound weird but I setup my first ZTNA ssh proxy and it works.  However, in the firewall policy I have defined a few tags that can use the policy.  The tags are different ActiveDirectory Groups our EMS has picked up.

 

So I have a tag for the Operations group (which I am a member of) and a tag for the QA group which I am not a member of.  Then we have a tag called EXAMPLE which is our entire AD domain.  All users in our domain are a member of this tag.

 

When the firewall policy only has the tags Operations and QA with a match ANY I get a deny for this policy.  If I add the tag EXAMPLE to the policy I can use it.

 

My question is is there a diagnose command I can run to see how the FortiGate is going through the policy and trying to determine if a users tag is a match or not?

2 REPLIES 2
Anthony_E
Community Manager
Community Manager

Hello,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Anthony-Fortinet Community Team.
Anthony_E
Community Manager
Community Manager

Hello,

 

To trace ZTNA posture tags in a policy, follow these steps:

  1. Access FortiOS: Log into your FortiGate device where the ZTNA policies are configured.
  2. Navigate to ZTNA Tags: Go to Policy & Objects > ZTNA > ZTNA Tags. Here, you can view the synchronized ZTNA tags that are used in your policies.
  3. Review Tagging Rules: Ensure that the tagging rules are correctly defined in FortiSASE. These rules specify the attributes that are checked on the FortiClient endpoint.
  4. Check Policy Configuration: Go to Policy & Objects > IPv4 Policy or Policy & Objects > IPv6 Policy, depending on your network configuration. Review the policies that use ZTNA tags to ensure they are correctly applied.
  5. Monitor and Verify: Use the Security Posture Tag Monitor in FortiClient EMS to verify that the correct tags are being applied to endpoints. This helps ensure that the posture checks are functioning as expected.

 

Regards,

Anthony-Fortinet Community Team.
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors