Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
sschuster
New Contributor II

ZTNA Access Denied with Forticlient on Fedora

Dear colleagues,

 

I don't get ZTNA running with Forticlient on Fedora Linux. I always get the massage

 

"ZTNA Access Denied
The page you requested has been blocked by a ZTNA restriction.

Details: Invalid ZTNA client certificate"

 

I tried Firefox, Chromium and Brave as Browsers but got the same result.

I rejoined the client to EMS, I reinstalled Forticlient but no change. Is there someone with the same problem or anybody who could help?

 

Forticlient 7.2.2.0753

EMS Forticloud

Fortigate 7.0.12

 

 

kind regards

stephan

1 Solution
sschuster
New Contributor II

At the end I could fix it by using another device. It was not working on my Lenovo T480 together with Linux even though it is working on T480 with windows. So just be informed that you may have trouble with some devices and Linux by using Forticlient which can maybe not be solved.

best

stephan

View solution in original post

13 REPLIES 13
sschuster
New Contributor II

I could not find out why the endpoints not showing up. I removed the Fabric Connector between Fortigate and EMS Cloud and connected them again. But no change. The Fortigate does not know my Linux Endpoints even they are listed in EMS (online, off-fabric, everything looks normal there). The ZTNA Documentation says

"Based on the client information, EMS applies matching Zero Trust tagging rules to tag the clients. These tags, and the client certificate information, are synchronized with the FortiGate in real-time. This allows the FortiGate to verify the client's identity using the client certificate, and grant access based on the ZTNA tags applied in the ZTNA rule."

 

This seems to be not working for me. The Tags are synced but not the Client Certificates. Any Ideas?

 

sschuster
New Contributor II

Because there are only Widows clients in the Endpoint Record List I focused on trying to find out if there is a general misconfiguration or if it is a Linux/Linux client related issue. I added new Clients. A MacOS client, another Fedora Client and a Ubuntu Client (VM on my machine). It worked immediately for the MacOS Client but for none of the Linux clients. So it must be something related to Linux or the Forticlient on Linux.

sschuster
New Contributor II

At the end I could fix it by using another device. It was not working on my Lenovo T480 together with Linux even though it is working on T480 with windows. So just be informed that you may have trouble with some devices and Linux by using Forticlient which can maybe not be solved.

best

stephan

VinayHM

Hi @sschuster 

 

I am glad that the issue is isolated :)

 

Regards,

 

Vinay HM
Labels
Top Kudoed Authors