Skip to main content
choee840408
Explorer
September 1, 2025
Question

Assistance Required – FortiAuthenticator SAML Integration with FortiGate IPsec VPN

  • September 1, 2025
  • 9 replies
  • 1264 views

Dear Sir,

I am encountering an issue while configuring SAML integration between FortiAuthenticator and FortiGate IPsec VPN, and I would like to request your assistance.

Current requirements:

  • FortiAuthenticator as IdP

  • FortiGate as SP

Configuration steps taken so far:

1.Enabled SAML-related service ports on FortiAuthenticator

1.jpg

2.Configured SAML IdP General settings on FortiAuthenticator and exported the certificate

2.jpg

3.Configured Service Providers on FortiAuthenticator

3.jpg

4.Configured Single Sign-On on FortiGate

4.jpg

5.Created a User Group

5.jpg

6.Established an IPsec Tunnel

6.jpg

7.Test result: IPsec connection shows failure

7.jpg

I would greatly appreciate it if you could review the configuration steps above to check for any omissions or errors, and provide recommended troubleshooting methods to help complete the SAML and IPsec VPN integration.

Thank you very much for your support!

9 replies

gstefou
Explorer
September 1, 2025

Hi Cho, 

The SSO Login window shouldn't be looking like that... I guess there's something wrong with the settings on your FGT. 

 

First off, how's your FAC connected with your Gate? Is the FAC outside on your FortiGate's network ? 

 

1) Fortigate is using a default port for SAML Authentication (Port 1001, if im not mistaken).

Make sure this configured properly under the "config system global" settings. 

 

- Open SAML Service on the Firewall and set the port -

config system global
set auth-ike-saml-port 1001

 

2) In addition, you will have to spesify the "FAC" SSO option under the interface your FAC is conected to the Firewall. If the FAC is outside of your network you will need to configure it on your internet faced interface (WAN Port). 

 

- Make SAML accessible from the internet exposed interface OR THE INTERFACE YOU HAVE THE FAC CONNECTED -

config system interface
edit wan1 <--- Use WAN Port only if FAC if outside of our network, outherwise use the interface you have the FAC connected to.
set ike-saml-server "FAC" <--- "FAC" is the Single Sign-On Name value you configured. 
end

choee840408
Explorer
September 1, 2025

 

Dear Sir,
Both the FAC and FG are on the internal network.
I will try the command you provided:

config system global
set auth-ike-saml-port 1001

However, does the IPsec VPN also need to be changed to IKEv2?
choee840408
Explorer
September 1, 2025

timeout

螢幕擷取畫面 2025-09-01 180411.jpg

GeorgeZhong
Staff & Editor
Staff & Editor
September 3, 2025

Hi @choee840408,

 

The SP's IP address needs to be <ipsec-vpn-gateway-fqdn/ip-address>:<saml-ike-authentication-port> as per document. In your case, as the SAML port is 1001, the SP IP address in the Single Sign On setting on both FGT and FAC should be 10.0.9.240:1001.

 

If this still doesn't work, please collect below debug log:

 

diagnose debug application ike -1

diagnose debug application samld -1

diagnose debug application fnbamd -1

diagnose vpn ike log filter rem-addr4 <client's public IP>

diagnose debug console timestamp enable

diagnose debug enable

 

Regards,

George

choee840408
Explorer
September 8, 2025

Dear All,
Thank you all for your help. The issue has been resolved. The cause was that the SP configuration on my FortiGate did not have the certificate enabled, which led to the connection failure. After enabling it, everything is working fine now. Thanks again!

4.jpg
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.