Skip to main content
Vanja98
New Member
September 26, 2025
Solved

FortiGate IKEv2 + SAML (Microsoft Entra ID) — “Firewall Authentication Failed” after MFA

  • September 26, 2025
  • 2 replies
  • 1797 views

Hello everyone,

 

We’re looking for guidance on an issue with FortiGate IKEv2 + SAML (Microsoft Entra ID). Below are the key details and symptoms.

 

Environment

Appliance: FortiGate 201G

FortiOS: v7.6.4 build3596 (Feature)

 

Symptoms

FortiClient opens the Microsoft Entra sign-in page and we receive the MFA push.

After approving MFA, the client returns “Firewall Authentication Failed.”

We are not able to access the ACS URL from the web. We get this page can’t be reached.

 

What we did
We followed the community article for Microsoft Entra ID SAML with FortiGate IPsec (IKEv2) and Fortinet’s official IPsec+SAML guide step by step, but the issue persists.

 

Firewall auth failed.jpg

 

Note: Before switching, we were using RADIUS for authentication and it was working.

 

Any advice on additional checks or known caveats with FortiOS 7.6.4 for IKEv2 + SAML would be appreciated. Thank you!

2 replies

funkylicious
SuperUser
SuperUser
September 26, 2025
Vanja98
Vanja98Author
New Member
September 26, 2025

Thank you for the quick help—your guidance did the trick. We’re authenticating successfully now.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.