Fortinet white logo
Fortinet white logo

SPA with a FortiGate SD-WAN Deployment Guide

Configuration workflow

Configuration workflow

You can follow this configuration workflow, which the document describes in detail using the example configuration of a dynamic private access policy that allows access to private applications, which in this example is a private server behind the FortiGate hub:

  1. Configure a zero trust network access (ZTNA) tagging rule set for compliant endpoints.
  2. Configure a ZTNA tagging rule set for non-compliant endpoints.
  3. Configure a dynamic private access policy to allow access to a specific private server from compliant endpoints.
  4. Configure a dynamic private access policy to deny access to a specific private server from non-compliant endpoints.
  5. Test the dynamic private access policies using ICMP ping to the specific private server from a compliant endpoint and from a non-compliant endpoint, respectively.
Note

A similar workflow applies to a private access policy that allows or denies access to applications of any other protocols besides ICMP, such as TCP or UDP applications.

Configuration workflow

Configuration workflow

You can follow this configuration workflow, which the document describes in detail using the example configuration of a dynamic private access policy that allows access to private applications, which in this example is a private server behind the FortiGate hub:

  1. Configure a zero trust network access (ZTNA) tagging rule set for compliant endpoints.
  2. Configure a ZTNA tagging rule set for non-compliant endpoints.
  3. Configure a dynamic private access policy to allow access to a specific private server from compliant endpoints.
  4. Configure a dynamic private access policy to deny access to a specific private server from non-compliant endpoints.
  5. Test the dynamic private access policies using ICMP ping to the specific private server from a compliant endpoint and from a non-compliant endpoint, respectively.
Note

A similar workflow applies to a private access policy that allows or denies access to applications of any other protocols besides ICMP, such as TCP or UDP applications.