Skip to main content
anarine
Visitor III
October 24, 2024
Question

Forticlient vpn on mobile fails to connect SAML if MFA is enabled

  • October 24, 2024
  • 4 replies
  • 2831 views

I use the free forticlient vpn on android phone and saml/sso authentication with azure user works fine.

However if the user has MFA, and after I enter the user's MFA code on the screen, the connection drops. Seems to be an issue with the mobile android client ?

If I enter the code on a Separate device, the connection succeeds. I have tried to set the app to "always on top" but issue persists.

 

4 replies

spoojary
Staff
Staff
October 24, 2024
Sgagan
Staff
Staff
October 24, 2024

Hello,

Could you also mention the FortClient version that you are using on the affected android device?

arahman
Staff
Staff
October 24, 2024

Hi, can you please also share the screen shot of the error you are seeing, also here is an article worth checking

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Android-device-SSL-VPN-Connection-Failed/ta-p/242594 

anarine
anarineAuthor
Visitor III
October 24, 2024

Yes the global remoteauthtimeout setting is set to 300. 

Everything works fine on fortivpn client on my windows pc.
 
On Android phone forticlient 7.4.0.0171-
SSLVPN saml MFA works fine. But IKE2 saml MFA fails whenever the code is entered on the Same android phone client. There is No error message. It's like the forticlient forgets it needs to connect after successful authentication. 
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!