Technical Tip: SSL/TLS deep inspection is required for session-based authentication
| Description | This article describes what settings are required to configure session-based authentication. |
| Scope | FortiGate v7.0+. |
| Solution | By default, FortiGate uses IP-based authentication while configuring SAML authentication in a proxy policy.
In a certain scenario (such as the end users accessing from a VDI environment), session-based authentication is required, which can be achieved by disabling IP-based, and enabling web-auth-cookie:
SSL/TLS deep inspection allows FortiGate to inspect HTTPS traffic. All the authentication rules based on the web-auth-cookie need to have SSL/TLS deep inspection enabled.
When leveraging SAML authentication with FortiGate running as a proxy (both explicit web proxy and transparent web proxy), in addition to the configuration for the IP-based authentication, the following settings need to be applied.
A successful session-based authentication with SAML looks like below:
|
