Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
aguerriero
Contributor II

ZTNA wildcard fqdn destination not working

I added a wildcard ztna destination.

 

*.domain.com:3389

When I do nslookups I get the VIP address for every host I try to connect to in that domain. When trying to connect via RDP nothing happens with the fortclient. The fortitcs log doesn't show anything happening.

I am using this link to set it up following the method 1 instructions. Step 2 is a little confusing as this looks like it was just copy and paste instructions from a previous version of EMS since adding ZTNA destinations is a little more involved than that.
https://docs.fortinet.com/document/forticlient/7.2.0/new-features/397618/wildcard-support-for-ztna-f... 

2 REPLIES 2
pmeet
Staff
Staff

I would recommend checking the logs and configuration on the FortiGate as well if the request is even getting sent to the FortiGate or not 

PATELMM
aguerriero

diagnose wad debug enable category all

diagnose wad debug enable level verbose

diagnose debug enable

Nothing from that client is shown on the fortigate. If I create a personal destination in the forticlient using the fqdn (hostname.domain.com:3389) that works just fine and I can connect to the specified servers. 

Labels
Top Kudoed Authors