Skip to main content
hbac
Staff
Staff
March 7, 2025

Troubleshooting Tip: Blank screen on FortiClient while connecting to a Dial-Up tunnel using SAML authentication

  • March 7, 2025
  • 0 replies
  • 3806 views
Description

This article describes an issue when a user tries to connect to a Dial-Up VPN tunnel using SAML authentication, and the FortiClient shows a blank screen after authenticating on the SAML login page (Azure in this example). 

 

blank page.PNG

Scope FortiOS v7.2.0 and above, FortiClient v7.2.4 and above. 
Solution

This issue occurred due to SAML URLs misconfiguration. To configure a Dial-Up VPN tunnel using SAML authentication, 'auth-ike-saml-port' must be specified in the CLI. By default, the port is set to 1001, and in this example, it is set to port 10443. 

 

config system global

    set auth-ike-saml-port 10443 <-- default port = 1001.

end 

 

However, the SAML URLs did not include port 10443 on both FortiGate and Azure. 

 

SAML.PNG

 

Azure.PNG

 

To resolve the issue, include port 10443 in the URLs on both FortiGate and Azure sides. After modifying the URLs, it is necessary to download the certificate from Azure again and re-import it to the FortiGate. 

 

Fixed urls.PNG

 

Azure URLs.PNG

 

Related article: 

Technical Tip: How to configure Microsoft Entra ID... - Fortinet Community

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.