Task 1 - FortiWeb Policy setup

FortiWeb Policy setup

  1. Before creating ZTNA profiles and Tags, We need to create a Server policy on FortiWeb. To create a server policy set up a server pool on FortiWeb.

    In Server Objects » Server Pool » Create new » Enter as shown below » Click OK

    fwebztna02 fwebztna02

  2. Click Create New to create a new server in Server pool as below.

    fwebztna03 fwebztna03 fwebztna04 fwebztna04

  3. Now, Create a Virtual Server. Server Objects » Virtual Server » Create new » click OK

    fwebztna05 fwebztna05

Now we will create a Virtual Server to listen on Port1 IP address

fwebztna06 fwebztna06

fwebztna07 fwebztna07

  1. Create a certificate in Server Objects » Certificates » CA Group

    cert01 cert01

  2. Create New CA group for FCTEMS and click OK.

    cert02 cert02

  3. Select Type CA, Select CA for FCTEMSXXXXXXX certificate as the CA, Click OK.

    cert03 cert03

    cert04 cert04

  4. Create a Server policy , in Policy » Server Policy » Create New as shown below.

fwebztna08 fwebztna08

  1. For Server pool, Virtual Server select the objects you created in Step 2 and 3. For HTTPS service select HTTPS

fwebztna09 fwebztna09

  1. Click Advanced SSL settings, For Certification verification for HTTPS click create new:

    cert05 cert05

  2. In the New Certificate Verify Tab, select the CA you have created earlier in Step 6. Finally Clik OK on the server policy.

    cert06 cert06

ZTNA Policies on FortiWeb

  1. Before setting up FortiWeb ZTNA rules, check if the ZTNA tags synced from FortiClient EMS to FortiWeb. On FortiWeb navigate to ZTNA » ZTNA profile » ZTNA tags. FortiWeb Might have to scroll to the end to see the tags created in earlier step.

    fwebztna fwebztna

  2. Create ZTNA rules to access the FortiWeb Web Server. Click OK.

    fwebztna101 fwebztna101

  3. Click on Add Condition, Select Type: ZTNA Tag, from Tag list Windows, Match condition: Any, click OK.

fwebztna11 fwebztna11

  1. In ZTNA profile, Create ZTNA profile with name WebServerAccess, Set Default action to Alert and Deny. Click OK.

    fwebztna12 fwebztna12

  2. For ZTNA Profile Member » Create new » Update to Add the rule you created in Step 9.

    fwebztna10 fwebztna10

    fwebztna14 fwebztna14

  3. Now go back to Server Policy » Policy » Edit the existing Policy.

    Scroll down to ZTNA profile and assign the profile created in previous step and click Save.

    fwebztna15 fwebztna15