Preparing for deployment
Before beginning your deployment, consider the components and licenses necessary for deploying the Zero Trust application gateway.
Basic Zero Trust application gateway components
The basic components that are required and recommended to configure ZTNA are:
-
(Required) FortiGate-VM application gateway
-
(Required) FortiClient EMS running version 7.0.0 or later or FortiClient EMS Cloud
-
(Required) FortiClient running 7.0.0 or later
-
(Recommended) FortiAuthenticator and FortiToken for centralized authentication and MFA
-
(Recommended) FortiTrust for cloud-based centralized authentication and MFA
-
(Recommended) FortiAnalyzer logging
For more information, see Design Components in the ZTNA Architecture Guide.
Licenses
The basic licenses that are required to configure ZTNA are:
-
FortiGate-VM license for BYOL cloud deployment.
-
Valid support license for the FortiGate-VM to support firmware upgrades and basic FortiGuard updates.
-
FortiClient Cloud ZTNA license with enough seats to support the number of FortiClient endpoints.
-
(Optional) NGFW subscriptions for the FortiGate-VM are not required, but can be purchased if security inspection related features are needed.
-
(Optional) FortiAuthenticator and FortiToken licenses for on-premise centralized authentication and MFA.
-
(Optional) FortiTrust subscription for cloud-based centralized authentication and MFA.
-
(Optional) FortiAnalyzer license.