Skip to main content
Fortizaid
Staff
Staff
February 20, 2026

Troubleshooting Tip: FortiClient User unable to connect to IPsec VPN using SAML authentication

  • February 20, 2026
  • 0 replies
  • 1090 views
Description This article describes a scenario where a FortiClient VPN user is unable to connect to an IPsec VPN using SAML authentication, and the user receives no SAML redirect page for idp authentication. Instead, the FortiClient shows the message 'vpn connection is down'.
Scope FortiGate.
Solution

FortiGate is configured to use an SAML server for authentication for IPsec VPN. When trying to log in to the IPsec VPN through FortiClient, the SAML redirect page for IDP authentication in FortiClient does not load. Instead, the error 'vpn connection is down' appears for a few seconds before closing. 

 

Troubleshooting steps to verify and isolate the point of fault:

  1. Check the FortiClient user trace logs: FortiClient -> Settings -> About -> Diagnostic Tool, then select the option called "Run". The logs will generate, and these logs can be accessed through the following path: FCDiagData -> General -> Logs -> Trace.

  2. Analyze the user trace logs, and the following error is observed:


[2025-12-23 14:57:23.4113953 UTC-07:00] [9396: 9400] [FortiVPN error 2389] !!! fortivpn::StateMachine::HandleTunnelDisconnected session 1 (TestDomain\Testuser) "Production IPSec" disconnected unexpectedly!

 

Also, run the following debugs on the FortiGate when attempting to connect to the VPN

FortiGate IKE/SAML debug:
 
      diagnose debug reset
      diagnose vpn ike log-filter src-addr4 <client-public-IP>
      diagnose debug console timestamp enable
      diagnose debug application ike -1
      diagnose debug application samld -1
      diagnose debug enable

 

 Replace <client-public-IP> with the FortiClient public IP.

 

After capture, run:

 

diagnose debug disable; 

diagnose debug reset

 

  1. Based on the previous trace log output, the Testuser from the TestDomain is unable to connect to the IPsec VPN tunnel named Production IPSec. The VPN disconnects unexpectedly. Also, there is no SAML redirect page for IDP authentication; the following FortiGate SAML setting needs to be verified:


config system interface
    edit "Interface-name"
        set ike-saml-server <saml server name>
end

  1. Ensure that the previous setting is applied to the correct physical interface where the IPsec VPN tunnel traffic is initiated. 

     

Resolution:

After the ike-saml-server configuration setting is applied to the correct interface, the SAML redirect page for IDP authentication in FortiClient will be able to load, and the user will be able to connect. 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.