The Answer is C
API gateway cannot be matched:
When connecting to the ZTNA access proxy, the client tries to connect to an API gateway that does not match any virtual host.
take from fortinet Docs: https://docs.fortinet.com/document/fortigate/7.0.0/new-features/608477/ztna-logging-enhancements-7-0-1
Its meen that is no firewall policy to the server that client want to access
C.
Empty Client Certificate = "Denied: empty client certificate"
Failed Client Certificate = "Denied: client certificate authentication failed"
API gateway that does not match any virtual host = "Denied: failed to match an API-gateway"
API gateway but the real server cannot be reached = "Denied: failed to match an API-gateway"
A ZTNA rule (proxy policy ) cannot be matched = "Denied: failed to match a proxy-policy"
HTTPS SNI virtual host does not match the HTTP host header = "Denied: failed to match an API-gateway"
=======================
Wrong Access Proxy
Right Access Proxy, down/missing Real Server
Right Access Proxy, wrong URI
======================
ZTNA Server = defines the access proxy VIP and the real servers that clients will connect to
ZTNA Rule (Proxy Policy) = enforce access control
Firewall Policy (Full ZTNA) = The firewall policy matches and redirects client requests to the access proxy VIP.
The answer is D.
Page 238 of the study guide reads, "This slide shows the UTM and traffic logs that are generated when FortiGate connects to the ZTNA access
proxy but is unable to match the ZTNA rule (proxy policy). For example, no ZTNA rule is matched for the ZTNA tag assigned to the endpoint."
I had now way to paste the slide but if you check page 238 you will see the slide with the logs.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Tomer676
Highly Voted 11 months agojr01239a
Highly Voted 10 months agoWanduka
Most Recent 3 months, 2 weeks agojohnnd
4 months, 4 weeks agoerosramos322
5 months, 3 weeks agoaguilazoo
11 months, 3 weeks agomhizha
12 months agoEggrolls
4 months, 4 weeks ago