Skip to main content
nflnetwork29
Explorer III
May 22, 2025
Question

Can't Set xauthtype saml on FortiOS 7.4.7 for IPsec VPN

  • May 22, 2025
  • 2 replies
  • 793 views

Hi all,

Trying to set up FortiClient IPsec VPN (IKEv2) with SAML (Microsoft Entra ID) on FortiOS 7.4.7. When I try set xauthtype saml or set saml-server, I get parse errors (code -61). Also getting psksecret required errors if I skip PSK.

Docs don’t mention any prerequisites. Has anyone gotten this working with Entra ID? Seems like the tunnel needs to be created in a specific order.

Thanks!

2 replies

Anthony_E
Staff
Staff
May 26, 2025

Hello,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Best Regards
Anthony_E
Staff
Staff
May 27, 2025

Hello,

 

To configure a FortiClient IPsec VPN (IKEv2) with SAML (Microsoft Entra ID) on FortiOS 7.4.7, ensure that your Entra ID environment is set up, and follow the detailed configuration steps for SAML authentication. Check for syntax errors and ensure compatibility with FortiClient and FortiOS versions.

 

Hope it helps.

 

Regardsm

Best Regards
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!