Fortinet white logo
Fortinet white logo

SPA with a FortiGate SD-WAN Deployment Guide

Testing private access connectivity to FortiGate hub network from remote SWG users

Testing private access connectivity to FortiGate hub network from remote SWG users

Note

This example requires System > SWG Configuration and Configuration > SWG User SSO to be configured appropriately. See SWG client onboarding and Configuring FortiSASE with Entra ID SSO in SWG agentless mode.

By default, all SWG users can access all private access resources. You can limit SWG user access to private access resources by creating a private access policy for SWG users. See Configuring a private access policy for SWG users.

You can verify access to the FortiGate hub network from FortiSASE SWG users by using a web browser to access a host on the hub local network.

For example, consider the case when a host on the hub local network has an HTTP server running on 10.100.99.101 and only the default private access policy for SWG users is in place in FortiSASE.

To test private access connectivity to FortiGate hub network from remote SWG users:
  1. From a web browser configured for SWG enter http://10.100.99.101.
  2. If this is the first time going out to the internet, you will be prompted by SAML SSO to enter your credentials.
  3. After entering your credentials, you should be able to access the web site at http://10.100.99.101 .

Testing private access connectivity to FortiGate hub network from remote SWG users

Testing private access connectivity to FortiGate hub network from remote SWG users

Note

This example requires System > SWG Configuration and Configuration > SWG User SSO to be configured appropriately. See SWG client onboarding and Configuring FortiSASE with Entra ID SSO in SWG agentless mode.

By default, all SWG users can access all private access resources. You can limit SWG user access to private access resources by creating a private access policy for SWG users. See Configuring a private access policy for SWG users.

You can verify access to the FortiGate hub network from FortiSASE SWG users by using a web browser to access a host on the hub local network.

For example, consider the case when a host on the hub local network has an HTTP server running on 10.100.99.101 and only the default private access policy for SWG users is in place in FortiSASE.

To test private access connectivity to FortiGate hub network from remote SWG users:
  1. From a web browser configured for SWG enter http://10.100.99.101.
  2. If this is the first time going out to the internet, you will be prompted by SAML SSO to enter your credentials.
  3. After entering your credentials, you should be able to access the web site at http://10.100.99.101 .