Fortinet black logo

ZTNA configurations and firewall policies

ZTNA configurations and firewall policies

Since FortiOS 7.0.2, ZTNA configurations no longer require a firewall policy to forward traffic to the access proxy VIP. This is implicitly generated based on the ZTNA rule configuration.

When upgrading from FortiOS 7.0.1 or below:

  • If an access-proxy type proxy-policy does not have a srcintf, then after upgrading it will be set to any.
  • To display the srcintf as any in the GUI, System > Feature Visibility should have Multiple Interface Policies enabled.
  • All full ZTNA firewall policies will be automatically removed.

ZTNA configurations and firewall policies

Since FortiOS 7.0.2, ZTNA configurations no longer require a firewall policy to forward traffic to the access proxy VIP. This is implicitly generated based on the ZTNA rule configuration.

When upgrading from FortiOS 7.0.1 or below:

  • If an access-proxy type proxy-policy does not have a srcintf, then after upgrading it will be set to any.
  • To display the srcintf as any in the GUI, System > Feature Visibility should have Multiple Interface Policies enabled.
  • All full ZTNA firewall policies will be automatically removed.