Skip to main content
ssanga
Staff & Editor
Staff & Editor
October 22, 2024

Technical Tip: OneLogin SAML SSL VPN Fails After Upgrade to FortiOS 7.0.15 or 7.4.3

  • October 22, 2024
  • 0 replies
  • 515 views
Description This article describes how to resolve an issue observed in FortiOS versions 7.0.15 or 7.4.3 where users are unable to connect to SSL VPN using OneLogin as the IdP after performing an upgrade.
Scope FortiGate v7.0.15, v7.4.3.
Solution

After upgrading FortiGate to FortiOS v7.0.15 or v7.4.3, OneLogin SSL VPN users may be unable to connect to the VPN. The problem can be verified by examining the logs as outlined below.

diagnose debug application samld -1
diagnose debug application sslvpnd -1
diagnose debug enable
.
.
2024-04-24 11:40:39 [15580:root:a]req: /remote/saml/login
2024-04-24 11:40:40 [15580:root:a]readPostLeave:151 invalid character (13) in payload (/remote/saml/login).


This issue has been resolved in v6.4.16, v7.2.9, v7.4.5, v7.6.0.

Logs required by FortiGate TAC for investigation:

  1. Debugs:

    diagnose debug application samld -1
    diagnose debug application sslvpnd -1
    diagnose debug timestamp enable
    diagnose debug enable
    <Reproduce the issue>
    diag debug disable

  2. TAC Report: 

 

execute tac report

 

  1. The configuration file of the FortiGate.

 

To disable the debug processes, press 'Ctrl+C' and enter 'diagnose debug disable'.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!