Palo Alto Panorama to Fortinet Gateway & EMS Migration Guide
Extracted straight from engineering discussions. These design compromises are built into the automated workflows to avoid network degradation and support programmatically scaleable configurations.
To avoid loading 5,200+ address objects through the restricted FortiClient EMS GUI pagination, developers bypass the portal entirely by generating the ZTNA destination XML profiles programmatically and pushing them via the back-end.
Non-HTTP application gateways (such as ShakeAlert ports 5671 and 8883) map externally to prepended numbers (e.g. 25671) on the FortiGate, which performs reverse port translation back to standard ports at destination real servers.
ZTNA connections are validated against multi-factor endpoint templates (domain, firewall, antivirus, BitLocker). Specific tags are layered recursively using AND/OR parameters so client verification remains robust and automated.