Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
moseiz
New Contributor II

ztna onnet access issues

have implemented ztna with onpremise fortiems 7.2.12 . and its working fine apart  from  few users who when they come to office, they are unable to access some resources till i disconnect their forticlient and connect back. there seems to be leftover configs of ztna which don't clear when they come to office. any suggestion to resolve this?. the pc are correctly tagged as onnet thus all ztna configs are supposed to clear. From the affected endusers forticlient, the ztna destination are cleared but still they cannot access resources till i disconnect them from ems. all pcs are windows 11 laptops

 

nslookup of a resource resolves to a  ztna temp IP 

 

> webservwe1.contoso.com
Server: dc1.contoso.com
Address: 10.0.1.1

Non-authoritative answer:
Name: webservwe1.contoso.com
Address: 10.235.0.2


after disconnecting fortclient from ems, the pc resolves to correct IP

 

> webservwe1.contoso.com
Server: dc1.contoso.com
Address: 10.0.1.1

Name: webservwe1.contoso.com
Address: 10.0.1.20

2 REPLIES 2
AEK
SuperUser
SuperUser

I understand from your description that the on-fabric ZTNA profile is pushed but the proxy persists.

But is it the same with all clients? Is it the same on all Windows 11 clients? What about Windows 10 clients?

On the other hand I've seen some issues fixed just by uninstalling and reinstalling FCT on the client. Can you try?

AEK
AEK
vpolovnikov
Staff & Editor
Staff & Editor

"From the affected endusers forticlient, the ztna destination are cleared but still they cannot access resources till i disconnect them from ems."

Do you mean the ZTNA Destination tab (or another words ZTNA feature) is gone from FortiClient when they are in the office? Or ZTNA is still enabled but the on-net ZTNA profile doesn't have any destinations configured? If the latter, I'd try disabling ZTNA for on-net altogether. 

VP
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors