Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Fullmoon
Contributor III

ZTNA

does anyone here tried to configured their existing FG and FortiEMS for ZTNA setup?

Fortigate Newbie

Fortigate Newbie
8 REPLIES 8
skyegool
New Contributor II

Hi,

 

I did, tags worked awesome before, ZTNA added complexity, and you cant activate it via GUI (bug)

You must enable it via CLI

 

config firewall policy edit <ID> set ztna-status enable set ztna-ems-tag <ZTNA_TAG_NAME? next end

 

 

 

Fullmoon

skyegool wrote:

Hi,

 

I did, tags worked awesome before, ZTNA added complexity, and you cant activate it via GUI (bug)

You must enable it via CLI

 

config firewall policy edit <ID> set ztna-status enable set ztna-ems-tag <ZTNA_TAG_NAME? next end

 

thanks for the response mate. So having FG and EMS/FortiClient are good enough for ZTNA setup?

 

 

 

Fortigate Newbie

Fortigate Newbie
martin28
New Contributor

It does not work for me, traffic not matching the policy.

peisenberg
Staff
Staff

Hi @Fullmoon 

Sorry for late response. Do you still need help with ZTNA ?

Pavol

TAC
shaibal_mitra
New Contributor

We are deploying ztna for the first time with fortisase and have had nothing but problems so far.Only RDP works and that takes for ever to load up.ssh does not work.Also using any ztna tags in policy breaks everything.Version is 7.0.9.

peisenberg

Hello

Can you please log a TAC ticket so we can assist you with your issue  ?

Thanks

 

Pavol

 

TAC
Sx11

Hi Shaibal,

 

for reference you can use following deployment types:

 

1.ZTNA HTTP Access proxy

https://docs.fortinet.com/document/fortigate/7.0.8/administration-guide/325639/ztna-https-access-pro...

 

2. ZTNA TCP forwarding:

https://docs.fortinet.com/document/fortigate/7.0.8/administration-guide/101256/ztna-tcp-forwarding-a...

 

Please refer to this link for concepts and guides:

https://docs.fortinet.com/ztna


Regards

sx11
peisenberg
Staff
Staff

Hello

Can you please log a TAC ticket so we can help you further ?

thanks

Pavol

TAC
Top Kudoed Authors