Technical Tip: SAML IDP redirect failures on Remote IPsec VPN connections
Description | This article describes an issue where users connecting to the IPsec remote VPN are not redirected to the SAML IDP for authentication. |
Scope | FortiGate. |
Solution | When the user is trying to connect to the IPsec remote VPN, the IDP login page is not loading. Â ![]() Â
 Configure the ike-saml-server under the concerned interface. Enable the ike-saml-server under the interface using this command:   Note: ike-saml-server can only be configured using CLI. The error could also occur if the ports being used on SAML Service Provider URL is different than what is set on auth-ike-saml-port under global config. Ensure they are the same :
Â
 Debugs to be taken if any issue occurs:  To disable: Â
Technical Tip: How to configure Microsoft Entra ID SAML authentication for Dial-up IPsec VPN SAML-based authentication for FortiClient remote access dialup IPsec VPN clients |

