Skip to main content
MHRNetwork
Explorer
January 3, 2024
Solved

Fortigate and Okta authentication integration

  • January 3, 2024
  • 7 replies
  • 4979 views

Hi all,

 

Previously I have implemented Fortigate integrate with Okta authen. but now we still having some issues which is I am not really sure about it.

 

Here is the config that I implemented in Fortigate

 

 

config user saml     edit "okta-idp"         set cert "Fortinet_Factory"         set entity-id "https://xxx.xxxx.xxx.xx:10443/remote/saml/metadata/"         set single-sign-on-url "https://xxx.xxxx.xxx.xx:10443/remote/saml/login/"         set single-logout-url "https://xxx.xxxx.xxx.xx:10443/remote/saml/logout/"         set idp-entity-id "http://www.okta.com/exxxxxxxxxxxxxxxxxxxxx"         set idp-single-sign-on-url "https://xxxxx-url.apac.xxxx.com/app/apac-xxxxx/xxxxxxxxxxxxxxxxx/sso/saml"         set idp-cert "REMOTE_Cert_1"         set user-name "username"         set digest-method sha256     next end   xxxxxfw01 (corporate-saml) # show config user group     edit "corporate-saml"         set member "okta-idp"         config match             edit 1                 set server-name "okta-idp"                 set group-name "corporate-saml"             next         end     next end

 

 

 

Firewall policy:

pppp.PNG

 

Debug output:

 

 

samld_send_common_reply [122]:     Attr: 17, 27, magic=178af1777bb9xxxx [336:vdom_xxxx:c117]fsv_saml_login_response:510 No group info in SAML response. [336:vdom_xxxx:c117]fsv_saml_login_response:514 No user name info in SAML response. Please check saml configuration. [336:vdom_xxxx:c117]fsv_saml_login_resp_cb:163 SAML response error: 3. [336:vdom_xxxx:c117]req: /remote/saml/login/(null) [336:vdom_xxxx:c117]def: (nil) /remote/saml/login/(null) [336:vdom_xxxx:c117]sslvpn_read_request_common,686, ret=-1 error=-1, sconn=0x7f0cf2a0af00. [336:vdom_xxxx:c117]Destroy sconn 0x7f0cf2a0af00, connSize=0. (vdom_xxxx)

 

 

 

Please let me know how to troubleshoot on this issue.

 

Thanks,

Best answer by hbac

@MHRNetwork,

 

Because the debug output saying 'No group info in SAML response.' which could be caused by attribute mismatch. That's why we need to verify the attribute. 

 

[336:vdom_xxxx:c117]fsv_saml_login_response:510 No group info in SAML response.
[336:vdom_xxxx:c117]fsv_saml_login_response:514 No user name info in SAML response. Please check saml configuration.

 

Regards, 

7 replies

funkylicious
SuperUser
SuperUser
January 3, 2024

Hi,

As the logs say, the username that you are trying to use is not part of corporate-saml group in Okta, that you have defined in your settings.

You can try and follow this link as a guide to configure SSLVPN with Okta : https://sites.google.com/frellsen.se/kimfrellsen/fortinet-ssl-vpn-with-okta-mfa-using-saml

"jack of all trades, master of none"
hbac
Staff
Staff
January 3, 2024

Hi @MHRNetwork,

 

Please verify the group attribute on both sides. Please refer to https://community.fortinet.com/t5/Support-Forum/Fortigate-and-Okta-authentication-integration/td-p/292188

 

Regards, 

MHRNetwork
Explorer
January 3, 2024

Hi hbac,

 

is that link correct? seems it redirect to this post.

 

thanks,

hbac
Staff
Staff
January 3, 2024

Hi @MHRNetwork,

 

Sorry, it was a wrong link. Please refer to https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configuring-SAML-SSO-login-for-SSL-VPN-web-mode/ta-p/192259

 

Regards, 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.