Troubleshooting Tip: FortiClient User unable to connect to IPsec VPN using SAML authentication
| Description | This article describes a scenario where a FortiClient VPN user is unable to connect to an IPsec VPN using SAML authentication, and the user receives no SAML redirect page for idp authentication. Instead, the FortiClient shows the message 'vpn connection is down'. |
| Scope | FortiGate. |
| Solution | FortiGate is configured to use an SAML server for authentication for IPsec VPN. When trying to log in to the IPsec VPN through FortiClient, the SAML redirect page for IDP authentication in FortiClient does not load. Instead, the error 'vpn connection is down' appears for a few seconds before closing.
Troubleshooting steps to verify and isolate the point of fault:
Also, run the following debugs on the FortiGate when attempting to connect to the VPN FortiGate IKE/SAML debug: diagnose debug reset
Replace <client-public-IP> with the FortiClient public IP.
After capture, run:
diagnose debug disable;
Resolution: After the ike-saml-server configuration setting is applied to the correct interface, the SAML redirect page for IDP authentication in FortiClient will be able to load, and the user will be able to connect. |
