Fortinet ZTNA Migration Automation Playbook

Palo Alto Panorama to Fortinet Gateway & EMS Migration Guide

Open GEMINI.md

Core Engineering Decisions

Extracted straight from engineering discussions. These design compromises are built into the automated workflows to avoid network degradation and support programmatically scaleable configurations.

XML Profile Overrides

To avoid loading 5,200+ address objects through the restricted FortiClient EMS GUI pagination, developers bypass the portal entirely by generating the ZTNA destination XML profiles programmatically and pushing them via the back-end.

External Port Maps

Non-HTTP application gateways (such as ShakeAlert ports 5671 and 8883) map externally to prepended numbers (e.g. 25671) on the FortiGate, which performs reverse port translation back to standard ports at destination real servers.

Posture (HIP) Tagging

ZTNA connections are validated against multi-factor endpoint templates (domain, firewall, antivirus, BitLocker). Specific tags are layered recursively using AND/OR parameters so client verification remains robust and automated.