Skip to main content
mark808
New Member
June 5, 2025
Question

Forticlient IPSEC SAML IOS QR code generator

  • June 5, 2025
  • 3 replies
  • 1251 views

Looking for info on creating the QR code for IOS ( deploying to about 100) with us replacing SSLVPN with IPSEC using SAML ( SSO )

3 replies

Jean-Philippe_P
Staff & Editor
Staff & Editor
June 7, 2025

Hello mark808, 

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible. 

 

Thanks, 

Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Staff & Editor
Staff & Editor
June 10, 2025

Hello,

 

We are still looking for an answer to your question.

 

We will come back to you ASAP.

 

Thanks,

Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Staff & Editor
Staff & Editor
June 10, 2025

Hello again mark808,

 

I found this solution. Can you tell us if it helps, please?

 

To create a QR code for deploying FortiClient IPsec with SAML on iOS devices, follow these steps:

  1. Generate the QR Code:
    - Go to System Settings > EMS Settings in your FortiClient EMS.
    - Ensure the FortiClient telemetry connection key field is populated if you want to include it in the QR code.
    - Click the View QR Code button beside the connection key field.
    - In the dialog, select or deselect Show FortiClient telemetry connection key as desired.
    - Click Continue.
    - Click Download to save the QR code image to your machine.

  2. Distribute the QR Code: Email the QR code to the FortiClient iOS users.

  3. Configure SAML for IPsec:
    - Ensure your FortiGate is configured for SAML-based authentication for IPsec VPN.
    - Follow the SAML configuration steps to integrate with your Identity Provider (IdP).

  4. Deploy to iOS Devices: Instruct users to scan the QR code using the FortiClient app on their iOS devices to automatically configure the VPN settings.

For detailed instructions on configuring SAML for IPsec, refer to the Fortinet documentation on SAML-based authentication for FortiClient remote access dial-up IPsec VPN clients.

Jean-Philippe - Fortinet Community Team