ZTNA configurations and firewall policies
Since FortiOS 7.0.2, ZTNA configurations no longer require a firewall policy to forward traffic to the access proxy VIP. This is implicitly generated based on the ZTNA rule configuration.
When upgrading from FortiOS 7.0.1 or below:
- If an
access-proxy
typeproxy-policy
does not have asrcintf
, then after upgrading it will be set toany
. - To display the
srcintf
as any in the GUI, System > Feature Visibility should have Multiple Interface Policies enabled. - All full ZTNA firewall policies will be automatically removed.