Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
huda
New Contributor

ztna

 how can I define a whitelist for applications That run on promise? Ems server #ems

3 REPLIES 3
AEK
SuperUser
SuperUser

Hi Huda

If you mean you want to allow specific application signature at firewall level, you need to do that:

  • Create an allow policy for your allowed applications, using ZTNA tag of your on premise clients as source
  • Just below the first policy, create a deny policy to deny all other traffic from the above mentioned clients

Ref:  https://docs.fortinet.com/document/forticlient/7.2.4/ems-administration-guide/424036/configuring-for...

AEK
AEK
huda
New Contributor

it works on .exe like googol chrome , i want to block the execution of applications running on promise like notion notepad ... so this solution works?  i think it can be possible just with fortiEDR

Sx11
Staff
Staff

Hi Huda,

 

IP/MAC based ZTNA is the suggested solution for on premise devices.

Example in doc below:

https://docs.fortinet.com/document/fortigate/7.2.7/administration-guide/477578/ztna-ip-mac-based-acc...

 

Regards

 

sx11
Labels
Top Kudoed Authors