Skip to main content
ManpreetSingh
Staff
Staff
February 16, 2026

Troubleshooting Tip: IPsec SAML VPN connection failure when accessing from FortiGate LAN interfaces

  • February 16, 2026
  • 0 replies
  • 1182 views
Description This article describes an issue where users are unable to establish an IPsec VPN connection using SAML authentication when they are connected to a LAN-side interface of a FortiGate (for example, Guest WiFi, internal LAN, or any other local interface).
Scope FortiGate.
Solution

Sometimes, when users are connected to a LAN interface on the FortiGate and IPsec VPN uses SAML authentication configured on the WAN interface, VPN connection fails during the SAML authentication redirect phase. The SAML login page will not load.

 

Root cause:


For IPsec VPNs using SAML authentication, the SAML server must be accessible via the same interface that handles the user’s web (browser) traffic during the authentication process.
If the SAML server is only configured on the WAN interface, users originating from a LAN interface will not be able to complete SAML authentication.

 

Solution:


Configure the SAML server on the LAN interface from which users initiate the VPN connection.

 

config system interface
    edit "Interface-name"
        set ike-saml-server <saml server name>
end

 

Repeat this configuration for any LAN interface from which users are expected to connect to the IPsec VPN using SAML authentication.

 

Related articles:

Technical Tip: How to configure Microsoft Entra ID SAML authentication for dial-up IPsec VPN

Technical Tip: FortiGate IPsec VPN configuration with Google SAML

SAML-based authentication for FortiClient remote access dialup IPsec VPN clients | FortiOS Administration Guide 

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!