Skip to main content
fabs
Visitor III
September 25, 2023
Question

cannot longer connect FortiClientVPN 7.2.2.0116 Azure SAML MFA

  • September 25, 2023
  • 31 replies
  • 44242 views

Hello,

 

since updating iPhone iOS from the last version 16 to the current 17.0.1, connecting via FortiClientVPN is no longer possible. The Azure SAML authentication takes place, but it stops at "Connection".
FortiClient VPN 7.2.2.0116
Fortigate 7.2.5 build1517
Can anyone here report the same problem?

31 replies

CrociStrike030
New Member
October 2, 2023

Same problem here. Multiple iPhones with iOS 16 or 17, and SAML to azure. Client is 7.2.2.0116. Is there any update coming soon to fix this issue?

xDivour
Visitor III
October 2, 2023

Any progress been made on Fortinets end? Experiencing the same issue. I did find if I disable MFA on my account or switch to foritoken the ForticlientVPN app works just not with Azure SAML. Same as other users the full version works.

Tofer
Visitor III
October 2, 2023

This is working for the EMS client, just NOT the FREE one, so its a catch-22 that Fortinet wont support it even if you have a TAM, and the TAM is worse than regular support.  Not the fault of the TAM at all, but a bad solution designed by Fortinet, its value is worthless.  BUT, has anyone tried this with the RADIUS to NPS way? instead of doing SAML directly from the firewall, have the fortigate talk to NPS RADIUS then have NPS do the communication to Azure.  I havent look at it in a while.  

f_sfetea
Visitor III
October 3, 2023

It seem SSO/SAML related as with local users I can connect

f_sfetea
Visitor III
October 3, 2023

Same issue here. I have opened a Case with TAC, it's in research

Netadmin-Japfa
New Member
October 5, 2023

I'm having same issue.
FortiOS v7.0.12 build0253
FortiClientVPN 7.2.2.0116
IOS v16.6.1

I hope Forti Dev team can fix this issue.

Morten1
Visitor III
October 5, 2023

I have the same problem client version 7.2.2.xxx

I have testet it with forti OS 6.4 and it stil work here but all 7.xx fails.

I have tried with SAML an local user both fails.

 

Can someone from fortigate please report back on this problem.

StefanRudat
Explorer
October 9, 2023

we have the same Problem with the iPhone App 7.2.2.016 IOS 17.0.3  .

Still no solution available ? 

kcheng
Staff & Editor
Staff & Editor
October 11, 2023

Hi,

 

Please try to disable DTLS setting in FortiGate and check if the issue still persists for iOS client:

config vpn ssl settings
    set dtls-tunnel disable
end

Rensjeh
Visitor III
October 11, 2023

Works for me; thank you!!

PBalochini
Explorer II
October 19, 2023

Problem finnaly solved by Miguel Cifuentes | TAC Engineer after adjusting :
  config vpn ssl settings
  set dtls-tunnel disable
  end
But the question is: This will open any security issues?

hbac
Staff
Staff
October 19, 2023

Hi @PBalochini,

 

No, dtls-tunnel uses UDP instead of TCP to improve performance. Disabling it will not pose any security risk. 

 

Regards, 

Support125
New Member
October 19, 2023

Hi,

 


I'm having the same the issue. I have tried to disable DTLS on FortiGate side and the connection succeed.

Do you have the same behaviour ?

 

kcheng
Staff & Editor
Staff & Editor
October 20, 2023

Hi @Support125 

 

This is the same behavior that we observed for users in this thread where iOS users with FortiClientVPN 7.2.2.0116 connecting to Azure SAML.