更改log 4引言5什么是什么新功能6 24.2.44(24.2.b)6的新功能24.2.12(24.2.a)6的新功能24.1.56(24.1.c)7的新功能24.1.37(24.1.37(24.1.b)的新功能what for what for 24.1.b)8什么是24.1.1.10(24.1.1.1.1.a)的新功能。 extension 11 Select availability features 13 Product integration and support 14 Supported FortiClient features 14 Common use cases 17 SIA for FortiClient agent-based remote users 18 SIA for FortiExtender site-based remote users 18 SIA for FortiGate SD-WAN secure edge site-based remote users 19 SIA for FortiAP site-based remote users 19 SIA for SD-WAN On-Ramp site-based remote users 19 Supported SD-WAN On-Ramp IPsec devices 20 Log forwarding 20 ZTNA 20 SPA 20 SPA Service Connection license 20 SPA FortiCloud account prerequisites 21 SPA using a FortiGate SD-WAN hub 21 SPA using a FortiSASE SPA hub 21 SPA using a FortiSASE SPA hub with Fabric overlay orchestrator 22 SPA for an MSSP hub 22 Resolved issues 23 Known issues 25 Limitations 26 FortiClient desktop (Windows, macOS, Linux) 26 FortiClient Android 26 FortiClient Cloud 26 Authentication 26 fortisandbox 27
SIA用于基于代理的远程用户是最典型的用例,它涉及在包括Windows,MacOS和Linux端点在内的支持端点上安装和配置ForticLient。Fortisase Administration指南称此用例基于ForticLient代理模式。在这种用例中,富特酶防火墙作为服务(FWAA)介于端点和互联网之间。因为ForticLient基本上建立了使用FWAAS的全隧道SSL VPN,因此基于代理的SIA可以使用VPN策略来确保所有互联网流量和协议。每个端点连接到安全性POP。您可以通过将身份验证源配置为Active Directory(AD)/LDAP,RADIUS或SAML身份提供商(SAML IDP)来实现基于代理的远程用户身份验证。
Change log 5 Introduction 6 What's new 7 What's New for 24.3.42 (24.3.b) 7 What's New for 24.3.20 (24.3.a) 8 What's new for 24.2.63 (24.2.c) 8 What's new for 24.2.44 (24.2.b) 10 What's new for 24.2.12 (24.2.a) 10 Special notices 12 On-shore Dubai customers 12 Removable media access 12 Activating the FortiClientNetwork extension 12 Select availability features 14 Product integration and support 15 Supported FortiClient features 15 Common use cases 18 SIA for FortiClient agent-based remote users 19 SIA for FortiExtender site-based remote users 19 SIA for FortiGate SD-WAN secure edge site-based remote users 20 SIA for FortiAP site-based remote users 20 SIA for SD-WAN On-Ramp site-based remote users 20 Supported SD-WAN On-Ramp IPsec devices 21 Log forwarding 21 Central management using FortiManager 21 ZTNA 21 SPA 21 SPA Service Connection license 22 SPA FortiCloud account prerequisites 22 SPA using a FortiGate SD-WAN hub 22 SPA using a FortiSASE SPA hub 22 SPA using a FortiSASE SPA hub with Fabric overlay orchestrator 23 SPA for an MSSP hub 23 Resolved issues 24 Known issues 26 Limitations 27 FortiAP 27 FortiClient desktop (Windows, macOS, Linux) 27 Forticlient Android 27 Forticlient Cloud 27 Forticloud 28身份验证28
更改日志5简介6什么是新的7新功能24.3.56(24.3.c)7 24.3.42(24.3.b)的新功能是24.3.20(24.3.a)9的新功能,什么是24.2.63(24.2.c)的新功能,什么是新功能(24.2.c)9什么是24.2.44.2.44(24.2.b)的新事物,for 24.2.44(24.2.b)11 for 24.2.2.2.2.2.2.1.2.2.1. 24.2.2.1. 24.2.12(24 d.2.12)(24 d.2.12)(24 d.2.12) 13 Removable media access 13 Activating the FortiClientNetwork extension 13 Select availability features 15 Beta features 16 Product integration and support 17 Supported FortiClient features 17 Common use cases 20 SIA for FortiClient agent-based remote users 21 SIA for FortiExtender site-based remote users 22 SIA for FortiGate SD-WAN secure edge site-based remote users 22 SIA for FortiAP site-based remote users 22 SIA for SD-WAN On-Ramp site-based remote users 23 Supported SD-WAN坡道IPSEC设备23日志转发23使用Fortimanager 23远程浏览器隔离24 ZTNA 24 ZTNA 24 SPA 24 SPA服务连接许可证24 Spa Forticloud帐户24 Spa使用Fortigate SD-WAN HUB 25 SPA使用Fortigate SD-WAN HUB 25 SPA使用Fortisase Spa Spa 25 Spa使用Fortisase Spa for Fortisase Spa 27 fortisase Spa 27 30限制31 Fortiap 31 Forticlient桌面(Windows,MacOS,Linux)31 Forticlient Android 31
a)Fortigate标志ForticLient提交的客户证书。这是错误的,因为FortiGate不会签署客户证书。
更改日志8简介9使用forticlient 11 SWG无代理模式12专用公共IP地址12嵌入到板载指南13 FORTFELEX许可16许可更新通知17远程VPN用户识别17所需的服务和端口17 AS IAM用户签名为IAM用户18遥控器22 23 fortect 22 22 fort fortigens 22 Fortigitig 22 fortigitig 22 support 26 Pre-logon VPN 26 ZTNA Windows tagging rules for certificate subject CN regex or wildcard matching 28 Central management 28 Network restrictions removed 29 SD-WAN On-Ramp support 30 Supporting external IdP users 30 Dashboards 31 Adding a custom dashboard 31 Resetting all dashboards 32 Drilling down on vulnerabilities 32 FortiView monitors 33 Adding a custom monitor 34 Resetting all monitors 34 Monitoring边缘设备带宽用法35边设备36边设备40 fortiextender 40先决条件40查看新的fortiextender的通知43将fortiextender配置为fortiextender fortiSase lan Extension 44 FortiGate 52先决条件53查看通知,以新的FortiGate 54配置FortiGate 54 FortiGate 54 Fortigate 54 Fortendies 54 Fortipecip 57
更改日志8入门9要求9许可10初始化Fortisase 11简介12使用FOTICLIENT 14 SWG无代理模式15专用公共IP地址15嵌入登机指南16 FORTIFLEX许可19所需的服务和端口19中的端口和端口19的签名24 iam用户识别24远程启用22远程启用22 external IdP users 25 Dashboards 26 Adding a custom dashboard 26 Resetting all dashboards 27 Drilling down on vulnerabilities 27 FortiView monitors 28 Adding a custom monitor 28 Resetting all monitors 29 Monitoring thin-edge bandwidth usage 29 Thin-Edge 31 Edge devices 33 FortiExtender 33 Prerequisites 33 Viewing notifications for a new FortiExtender 36 Configuring FortiExtender as FortiSASE LAN Extension 37 Fortigate 45先决条件46查看新的Fortigate 47将Fortigate配置为Fortigate fortigate 47 Fortiap 50 50先决条件50查看新的Fortiap 52 52将Fortiap配置为Fortisase Edge设备52 SD-WAN RAMP 65
当您使用深度检查时,Fortisase通过充当中介机构连接到SSL Server,用作中间机。它解密并检查内容以找到威胁并阻止它们。要解密流量,Fortisase充当CA,签署给收件人的真实服务器证书。Fortisase使用的CA证书将由Fortisase端点管理服务自动推送到端点的可信根CA证书存储。因此,ForticLient信任Fortisase使用的CA证书。因此,收件人在其浏览器上没有看到任何证书警告。
本指南探讨了Fortisase如何与Fortigate ZTNA集成,为最终用户提供无缝体验,同时确保您最重要的公司资产在FortiGate Application Gateway后面。与传统的SSL和IPSEC VPN不同,使用ZTNA的Fortisase Spa提供了与受保护资源的直接连接,而无需建立持续的隧道。ZTNA的钥匙正在验证连接设备和用户的身份,并确保设备的安全姿势在将其接纳到受保护的网络之前。由于Fortisase,FortiGate和ForticLient端点之间的集成,这些安全检查立即透明地进行。如果设备无法通过这些安全检查,则将其视为不信任,并且连接被拒绝。