Fortinet black logo

FortiGate NGFW to FortiSASE SPA Hub Conversion Deployment Guide

Configuring ZTNA rule sets to dynamically tag agent-based remote users

Copy Link
Copy Doc ID b10d503a-c519-11ee-8c42-fa163e15d75b:53540
Download PDF

Configuring ZTNA rule sets to dynamically tag agent-based remote users

This example demonstrates how to configure zero trust network access (ZTNA) tag names and ZTNA tagging rule sets with the following posture checks:

  • Endpoint is running Windows and has antivirus (AV) software installed and running
  • Endpoint is running Windows and does not have AV software installed or running
To configure a ZTNA tagging rule set for compliant endpoints:
  1. Go to Configuration > ZTNA Tagging, and click Create.
  2. In the Name field, enter the desired rule set name. For example, SASE-Compliant.
  3. Toggle Enabled on or off to enable or disable the rule.
  4. (Optional) In the Comments field, enter any desired comments.
  5. Under When the following rules match, click Create.
  6. Configure the Severity Level rule:
    1. For Operating System, select Windows.
    2. From the Rule Type dropdown list, select AntiVirus.
    3. From the AntiVirus dropdown list, select AntiVirus Software is installed and running.
    4. Click OK.
  7. In the Tag Name dropdown list, create a tag named SASE-Compliant.
  8. Click OK.

To configure a ZTNA tagging rule set for non-compliant endpoints:
  1. Go to Configuration > ZTNA Tagging, and click Create.
  2. In the Name field, enter the desired rule set name. For example, SASE-Non-Compliant.
  3. Toggle Enabled on or off to enable or disable the rule.
  4. (Optional) In the Comments field, enter any desired comments.
  5. Under When the following rules match, click Create.
  6. Configure the Severity Level rule:
    1. For Operating System, select Windows.
    2. From the Rule Type dropdown list, select AntiVirus.
    3. Select Negate.
    4. From the AntiVirus dropdown list, select AntiVirus Software is installed and running.
    5. Click OK.
  7. In the Tag Name dropdown list, create a tag named SASE-Compliant.
  8. Click OK.

Configuring ZTNA rule sets to dynamically tag agent-based remote users

This example demonstrates how to configure zero trust network access (ZTNA) tag names and ZTNA tagging rule sets with the following posture checks:

  • Endpoint is running Windows and has antivirus (AV) software installed and running
  • Endpoint is running Windows and does not have AV software installed or running
To configure a ZTNA tagging rule set for compliant endpoints:
  1. Go to Configuration > ZTNA Tagging, and click Create.
  2. In the Name field, enter the desired rule set name. For example, SASE-Compliant.
  3. Toggle Enabled on or off to enable or disable the rule.
  4. (Optional) In the Comments field, enter any desired comments.
  5. Under When the following rules match, click Create.
  6. Configure the Severity Level rule:
    1. For Operating System, select Windows.
    2. From the Rule Type dropdown list, select AntiVirus.
    3. From the AntiVirus dropdown list, select AntiVirus Software is installed and running.
    4. Click OK.
  7. In the Tag Name dropdown list, create a tag named SASE-Compliant.
  8. Click OK.

To configure a ZTNA tagging rule set for non-compliant endpoints:
  1. Go to Configuration > ZTNA Tagging, and click Create.
  2. In the Name field, enter the desired rule set name. For example, SASE-Non-Compliant.
  3. Toggle Enabled on or off to enable or disable the rule.
  4. (Optional) In the Comments field, enter any desired comments.
  5. Under When the following rules match, click Create.
  6. Configure the Severity Level rule:
    1. For Operating System, select Windows.
    2. From the Rule Type dropdown list, select AntiVirus.
    3. Select Negate.
    4. From the AntiVirus dropdown list, select AntiVirus Software is installed and running.
    5. Click OK.
  7. In the Tag Name dropdown list, create a tag named SASE-Compliant.
  8. Click OK.