Technical Tip: SAML Authentication Fails on Windows FortiClient Machines when SSL VPN Webmode is Disabled Globally
| Description | This article explains an issue where FortiClient users on Windows OS are unable to connect to SAML SSL VPN when SSL VPN web mode is globally disabled. |
| Scope | FortiGate v7.4.4. |
| Solution | SAML SSL VPN users may experience connection issues using FortiClient on Windows OS when SSL VPN web mode is disabled globally. However, when web mode is enabled, users can connect to the VPN without any problems. The problem can be verified by examining the logs as outlined below. User Agent is shown as 'null'. [3958:customer1:eb7]req: /remote/saml/start This issue has been resolved in v7.4.8 and v7.6.1 (available on the Fortinet Support Portal).
diagnose debug reset
Related article: Troubleshooting Tip: FortiClient SAML authentication when SSL VPN web mode is disabled globally |