Skip to main content
iteam
New Member
May 18, 2026
Question

FortiClient EMS - SAML Authentication

  • May 18, 2026
  • 1 reply
  • 59 views

We are currently testing the FortiClient EMS to switch from the free SSLVPN Client to IPSEC.

I have some questions.

 

Is it possible to create multiple dial-up vpn tunnels that authenticate against Azure AD via SAML?

When I enabled the option “set eap enable” and “set eap-identity send-request” for a second tunnel,

the connection via the first tunnel stopped working.


Is it supported to add a user to multiple Azure AD groups and then assign the groups to different firewall policies in order to implement granular access control?

 

We are using vpn split tunneling. I create a group which networks and hosts are routed through the tunnel.

I then assigned that group to the VPN tunnel ( Accessible Networks ). I there a member limit for the group? 

 

Currenty it ist not supported to use a fqdn address for ipsec dialup.

Are there any plans to support this?

 

1 reply

funkylicious
SuperUser
SuperUser
May 18, 2026

 

multiple dialup vpn tunnels could be an option , but you can create a single dialup vpn tunnel, create the groups that you require and reference them in the firewall rules

 

"jack of all trades, master of none"
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.