QuestionQ12

Zero trust network access (ZTNA) deployment

Refer to the exhibit.

Question Image

An administrator must provide on-fabric clients access to FortiAnalyzer by using ZTNA tags. Which two conditions must be satisfied to accomplish this task?

Choose two
  • A The on-fabric client should have FortiGate as its default gateway.
  • B The ZTNA server must be configured on FortiGate.
  • C The ZTNA rule must be configured on FortiClient.
  • D The IP/MAC based firewall policy must be configured on FortiGate.
Explanation

For on-net access, FortiGate enforces security-posture tags in a standard firewall policy through IP/MAC-based access control. Client traffic must traverse the FortiGate for that policy to apply, which requires FortiGate to be the client’s default gateway. This mode does not require a ZTNA access proxy or ZTNA server.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!