Troubleshooting Tip: IPsec SAML VPN connection failure when accessing from FortiGate LAN interfaces
| Description | This article describes an issue where users are unable to establish an IPsec VPN connection using SAML authentication when they are connected to a LAN-side interface of a FortiGate (for example, Guest WiFi, internal LAN, or any other local interface). |
| Scope | FortiGate. |
| Solution | Sometimes, when users are connected to a LAN interface on the FortiGate and IPsec VPN uses SAML authentication configured on the WAN interface, VPN connection fails during the SAML authentication redirect phase. The SAML login page will not load.
Root cause:
Solution:
config system interface
Repeat this configuration for any LAN interface from which users are expected to connect to the IPsec VPN using SAML authentication.
Related articles: Technical Tip: How to configure Microsoft Entra ID SAML authentication for dial-up IPsec VPN Technical Tip: FortiGate IPsec VPN configuration with Google SAML |
