Fortinet white logo
Fortinet white logo

Administration Guide

Prerequisites

Prerequisites

Note

Although you must configure SWG and SWG SSO to configure agentless ZTNA, you do not need to configure the remote user endpoints for SWG. In other words, you do not need to configure remote user endpoints with a proxy autoconfiguration file or with a CA certificate for SSL deep inspection.

The agentless ZTNA feature simply uses configuration from SWG and SWG SSO features for remote user authentication.

The following prerequisites are required to use agentless zero trust network access (ZTNA):

  • FortiSASE instance has the Advanced remote users license applied.
  • Secure web gateway (SWG) is configured on the FortiSASE instance.
  • SWG user single sign on (SSO) is configured.
  • The private web-based application to be accessed using agentless ZTNA fulfills the following:
    • Reside on the local network behind a FortiGate device
    • Support HTTPS
  • Secure private access (SPA) is licensed for the FortiGate device which will be the SPA hub. See SPA Service Connection license and SPA FortiCloud account prerequisites.
  • SPA is configured for BGP per overlay or BGP on loopback with the FortiGate device. See SPA.
Note

Agentless ZTNA does not work with SPA hubs configured with BGP on loopback and private web-based applications configured with the Server Type set to FQDN.

Prerequisites

Prerequisites

Note

Although you must configure SWG and SWG SSO to configure agentless ZTNA, you do not need to configure the remote user endpoints for SWG. In other words, you do not need to configure remote user endpoints with a proxy autoconfiguration file or with a CA certificate for SSL deep inspection.

The agentless ZTNA feature simply uses configuration from SWG and SWG SSO features for remote user authentication.

The following prerequisites are required to use agentless zero trust network access (ZTNA):

  • FortiSASE instance has the Advanced remote users license applied.
  • Secure web gateway (SWG) is configured on the FortiSASE instance.
  • SWG user single sign on (SSO) is configured.
  • The private web-based application to be accessed using agentless ZTNA fulfills the following:
    • Reside on the local network behind a FortiGate device
    • Support HTTPS
  • Secure private access (SPA) is licensed for the FortiGate device which will be the SPA hub. See SPA Service Connection license and SPA FortiCloud account prerequisites.
  • SPA is configured for BGP per overlay or BGP on loopback with the FortiGate device. See SPA.
Note

Agentless ZTNA does not work with SPA hubs configured with BGP on loopback and private web-based applications configured with the Server Type set to FQDN.