Configuration workflow
Ensure that you are aware of agentless ZTNA Prerequisites Reviewing the prerequisites is necessary before following the configuration workflow that follows. |
The workflow for configuring agentless zero trust network access (ZTNA) is as follows:
- Enable secure web gateway (SWG) from System > SWG Configuration. See SWG Configuration.
- Enable SSO authentication for SWG users. For a configuration example, see Configuring FortiSASE with Entra ID SSO in SWG agentless mode.
- Configure user groups for SWG users. See Users.
- Configure a Private Access security profile group. See Security profile groups.
Although you must configure SWG and SWG SSO to configure agentless ZTNA, you do not need to configure the remote user endpoints for SWG. In other words, you do not need to configure remote user endpoints with a proxy autoconfiguration file or with a CA certificate for SSL deep inspection.
The agentless ZTNA feature simply uses configuration from SWG and SWG SSO features for remote user authentication.
- Configure SPA for the FortiGate device acting as an SPA hub. See SPA.
Agentless ZTNA does not work with SPA hubs configured with BGP on loopback and private web-based applications configured with the Server Type set to FQDN.
- Configure access control based on the geolocation of the remote user, also known as geofencing, from the Configuration > Geofencing page. Geofencing applies not only to agentless ZTNA but all incoming remote user access such as remote user and edge device connectivity. See Geofencing.
- Configure a private application from the Configuration > Agentless ZTNA > Private applications tab. A private application is assigned to a custom domain name and added as a bookmark entry to the agentless ZTNA bookmark portal. See Configuring a private application.
- Configure an application policy using a user group, security profile group, and private application which were all configured in previous steps. See Configuring an application policy.
- Access the bookmark portal to see all configured private applications. See Accessing the bookmark portal.
- Verify agentless ZTNA access to the desired private web-based application. See Verifying agentless ZTNA functionality.