Skip to main content
funkylicious
SuperUser
SuperUser
June 23, 2026
Question

FortiClient Android IKEv2 SAML

  • June 23, 2026
  • 2 replies
  • 126 views

Hello,

Has anyone managed to get a working configuration for FortiClient on Android while using SAML?

According to the documentation this should be possible but for some reason I cannot seem to figure out this isnt working, something else that throws me off is the config with X.509 certificates in order to be able to configure the SAML port, while having EAP disabled and SSO enabled.

I have a working setup for windows clients working, a separate IPsec tunnel from the one I’ve conducted my tests using a networkid but on the Android phone after the IdP prompt where I enter the credentials it doesnt do anything.

FGT: 7.4.11

FCT: 7.4.6

IdP: Keycloak

2 replies

abelio
SuperUser
SuperUser
June 23, 2026

Hello
I understand that there's no support yet in Forticlient IOS or Android  for  EAP-TTLS/PAP authentication.
(I don´t find the link/doc right now, sorry)
If that matter continues, there's no IKEv2 support either, therefore no SAML auth.

Maybe some else in the forum could update this info or correct me.
I'm searching docs meanwhile to come back here

hope it helps
 

 

funkylicious
SuperUser
SuperUser
June 23, 2026

is this the doc in question ?

 

"jack of all trades, master of none"
abelio
SuperUser
SuperUser
June 23, 2026

indeed, 
I've added this in my internal notes, without reference..
 

Important note:

At the time of writing, FortiClient iOS and Android do not support EAP-TTLS/PAP authentication.

It 's a 2025's article, I dunno actually the status, but I believe that there has been no improvement on unlicensed forticlients

funkylicious
SuperUser
SuperUser
June 24, 2026

i dont think it’s only related ot unlicensed clients. i’ve also tried to connect the Android phone to EMS and it has the same behaviour.

"jack of all trades, master of none"