have implemented ztna with onpremise fortiems 7.2.12 . and its working fine apart from few users who when they come to office, they are unable to access some resources till i disconnect their forticlient and connect back. there seems to be leftover configs of ztna which don't clear when they come to office. any suggestion to resolve this?. the pc are correctly tagged as onnet thus all ztna configs are supposed to clear. From the affected endusers forticlient, the ztna destination are cleared but still they cannot access resources till i disconnect them from ems. all pcs are windows 11 laptops
nslookup of a resource resolves to a ztna temp IP
> webservwe1.contoso.com
Server: dc1.contoso.com
Address: 10.0.1.1
Non-authoritative answer:
Name: webservwe1.contoso.com
Address: 10.235.0.2
after disconnecting fortclient from ems, the pc resolves to correct IP
> webservwe1.contoso.com
Server: dc1.contoso.com
Address: 10.0.1.1
Name: webservwe1.contoso.com
Address: 10.0.1.20
I understand from your description that the on-fabric ZTNA profile is pushed but the proxy persists.
But is it the same with all clients? Is it the same on all Windows 11 clients? What about Windows 10 clients?
On the other hand I've seen some issues fixed just by uninstalling and reinstalling FCT on the client. Can you try?
"From the affected endusers forticlient, the ztna destination are cleared but still they cannot access resources till i disconnect them from ems."
Do you mean the ZTNA Destination tab (or another words ZTNA feature) is gone from FortiClient when they are in the office? Or ZTNA is still enabled but the on-net ZTNA profile doesn't have any destinations configured? If the latter, I'd try disabling ZTNA for on-net altogether.
Created on ā01-15-2026 09:51 PM Edited on ā01-15-2026 09:52 PM
when onnet the ztna profile is on but without any destination. have disabled the ztna when onnet as you suggested,will monitor and see.
| User | Count |
|---|---|
| 2910 | |
| 1451 | |
| 850 | |
| 825 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.