Fortinet white logo
Fortinet white logo
7.2.4

Preparing for deployment

Preparing for deployment

Before beginning your deployment, consider the components and licenses necessary for deploying the Zero Trust application gateway.

Basic Zero Trust application gateway components

The basic components that are required and recommended to configure ZTNA are:

  1. (Required) FortiGate-VM application gateway

  2. (Required) FortiClient EMS running version 7.0.0 or later or FortiClient EMS Cloud

  3. (Required) FortiClient running 7.0.0 or later

  4. (Recommended) FortiAuthenticator and FortiToken for centralized authentication and MFA

  5. (Recommended) FortiTrust for cloud-based centralized authentication and MFA

  6. (Recommended) FortiAnalyzer logging

For more information, see Design Components in the ZTNA Architecture Guide.

Licenses

The basic licenses that are required to configure ZTNA are:

  1. FortiGate-VM license for BYOL cloud deployment.

  2. Valid support license for the FortiGate-VM to support firmware upgrades and basic FortiGuard updates.

  3. FortiClient Cloud ZTNA license with enough seats to support the number of FortiClient endpoints.

  4. (Optional) NGFW subscriptions for the FortiGate-VM are not required, but can be purchased if security inspection related features are needed.

  5. (Optional) FortiAuthenticator and FortiToken licenses for on-premise centralized authentication and MFA.

  6. (Optional) FortiTrust subscription for cloud-based centralized authentication and MFA.

  7. (Optional) FortiAnalyzer license.

Preparing for deployment

Preparing for deployment

Before beginning your deployment, consider the components and licenses necessary for deploying the Zero Trust application gateway.

Basic Zero Trust application gateway components

The basic components that are required and recommended to configure ZTNA are:

  1. (Required) FortiGate-VM application gateway

  2. (Required) FortiClient EMS running version 7.0.0 or later or FortiClient EMS Cloud

  3. (Required) FortiClient running 7.0.0 or later

  4. (Recommended) FortiAuthenticator and FortiToken for centralized authentication and MFA

  5. (Recommended) FortiTrust for cloud-based centralized authentication and MFA

  6. (Recommended) FortiAnalyzer logging

For more information, see Design Components in the ZTNA Architecture Guide.

Licenses

The basic licenses that are required to configure ZTNA are:

  1. FortiGate-VM license for BYOL cloud deployment.

  2. Valid support license for the FortiGate-VM to support firmware upgrades and basic FortiGuard updates.

  3. FortiClient Cloud ZTNA license with enough seats to support the number of FortiClient endpoints.

  4. (Optional) NGFW subscriptions for the FortiGate-VM are not required, but can be purchased if security inspection related features are needed.

  5. (Optional) FortiAuthenticator and FortiToken licenses for on-premise centralized authentication and MFA.

  6. (Optional) FortiTrust subscription for cloud-based centralized authentication and MFA.

  7. (Optional) FortiAnalyzer license.