Fortinet black logo

Administration Guide

Configuring zero-trust network access (ZTNA) objects

Configuring zero-trust network access (ZTNA) objects

Firewall addresses and groups that support zero-trust network access (ZTNA) can be configured in FortiManager to support ZTNA syntax for firewall policies. For more information on ZTNA, see the FortiGate Administration Guide.

To configure a ZTNA firewall address:
  1. Ensure you are in the correct ADOM.
  2. Go to Policy & Objects > Object Configurations, and select Firewall Objects > Addresses from the tree menu.
  3. Click Create New, and select Address from the dropdown menu.
  4. In the Type field, select Dynamic.
    The Sub Type field is displayed.
  5. Select FortiClient EMS Tag as the sub type.
    The Object Type field is displayed.
  6. Select IP or MAC as the tag object type.
  7. Click OK to save the address object.
To configure a ZTNA firewall address group:
  1. Ensure you are in the correct ADOM.
  2. Go to Policy & Objects > Object Configurations, and select Firewall Objects > Addresses from the tree menu.
  3. Click Create New, and select Address Groups from the dropdown menu.
  4. Enable the ZTNA Tag toggle and select EMS or Geographic IP.
  5. In the Members section, configure members based on the address group type.
    • When the type is EMS, select group members from FortiClient EMS Tag address objects.
    • When the type is Geographic IP, select group members from Geometry address objects.
  6. Click OK to save the address group.

Configuring zero-trust network access (ZTNA) objects

Firewall addresses and groups that support zero-trust network access (ZTNA) can be configured in FortiManager to support ZTNA syntax for firewall policies. For more information on ZTNA, see the FortiGate Administration Guide.

To configure a ZTNA firewall address:
  1. Ensure you are in the correct ADOM.
  2. Go to Policy & Objects > Object Configurations, and select Firewall Objects > Addresses from the tree menu.
  3. Click Create New, and select Address from the dropdown menu.
  4. In the Type field, select Dynamic.
    The Sub Type field is displayed.
  5. Select FortiClient EMS Tag as the sub type.
    The Object Type field is displayed.
  6. Select IP or MAC as the tag object type.
  7. Click OK to save the address object.
To configure a ZTNA firewall address group:
  1. Ensure you are in the correct ADOM.
  2. Go to Policy & Objects > Object Configurations, and select Firewall Objects > Addresses from the tree menu.
  3. Click Create New, and select Address Groups from the dropdown menu.
  4. Enable the ZTNA Tag toggle and select EMS or Geographic IP.
  5. In the Members section, configure members based on the address group type.
    • When the type is EMS, select group members from FortiClient EMS Tag address objects.
    • When the type is Geographic IP, select group members from Geometry address objects.
  6. Click OK to save the address group.