A FortiGate administrator is deploying ZTNA to provide access to internal applications for remote users. The administrator wants to ensure that users can only access the specific applications they are authorized for, and that the ZTNA access proxy performs authentication and authorization before forwarding traffic. Which FortiGate component must be configured to define the protected applications and the authentication rules for ZTNA access?
The ZTNA server on the FortiGate defines the access proxy that protects internal applications. It includes the virtual host name, the server certificate used for TLS, and the application mappings that specify which internal resources are published and how they are accessed. Authentication and authorization are enforced through the ZTNA policy that references the ZTNA server, ensuring users only reach authorized applications.
Why this answer
The ZTNA server configuration on the FortiGate is the component that defines the access proxy, including the virtual host, server certificate, and application mappings for protected applications. The ZTNA policy then references this server to enforce authentication and authorization. Without the ZTNA server, there is no application-level proxy to control access, so users could not be restricted to specific applications.
Exam trap
The trap here is assuming that a standard firewall policy or SSL VPN portal can provide ZTNA application-level access control without a ZTNA server configuration.