Skip to main content
Connor_Johnson
New Member
May 6, 2022
Question

How to properly configure multiple SSO connections with a FortiGate

  • May 6, 2022
  • 2 replies
  • 4758 views

We have an HA pair of FortiGate 500E's. They are running 7.0.5

I have successfully configured SSO for our Split Tunnel portal and it is working. FortiClient successfully takes us to the identity provider which is JumpCloud and allows me to connect with the Split Tunnel access.

 

But we also have users that we want to use the Tunnel All portal. I have configured it the same way I did as the Split Tunnel but I think I need to somehow specify which one the user needs to connect to. And I am not sure how to do that specification. Does anyone have any ideas here?

2 replies

bpozdena_FTNT
Staff
Staff
May 6, 2022

You could technically configure authentication rules and match portals based on groups in SAML response. But it can get very complex and difficult to troubleshoot.

 

My recommendation is to create separate SSL VPN realms for your split and full portals. You can find a detailed guide here. The example uses Azure as SAML IdP, but the Fortigate and FortiClient configuration will be essentially the same. 

Connor_Johnson
New Member
May 6, 2022

Realms is exactly what I was looking for. Thank you! 

Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!