Skip to main content
ForgetItNet
Explorer II
July 23, 2025
Question

IPSEC SAML VPN... SSO works but then does not start the VPN connection

  • July 23, 2025
  • 4 replies
  • 3177 views

Hi all,

 

I've been working with support on this without any success so far (and they've confirmed all the setup is correct) but I'm trying to move from SSL VPN to IPSEC and have setup SAML with EntraID and this works fine when using the Apple App on iPads but I cannot get it going on a Windows machine. When I try to connect it prompts me to log into Azure and then says "you have successfully logged in" but that window just stays there and the FortiClient just shows as "Disconnect" but it's not actually connected whereas on the iPads it does the Azure bit and then that window disappears and the VPN starts to connect.

I've tried it with Windows 10 and 11 and also server 2016 and also with various versions of FortiClient and although I can see the SAML connecting in the logs on the FortiGate there is nothing after that i.e. it doesn't then start to connect the VPN, it's as though whatever should happen after that just doesn't happen.

I've got a feeling this is more of a Microsoft thing rather than a Fortinet thing so can I simply ask if anyone has got a Windows users connecting to a FortiGate using Entra SSO and IPSEC and if so then what version/release of Windows and FortiClient are you using so I can mirror it (we're not using EMS by the way just the free VPN) and also am I correct in thinking that when the SSO completes then should the "You have successfully logged on" window disappear and the VPN start to connect or is the process slightly different as it might help to know what I "should" be expecting ?

Any helps would be great.

4 replies

sharmar
Staff & Editor
Staff & Editor
July 24, 2025

Hello @ForgetItNet 

 

Are you trying Ipsec + SAML + External browser if yes then may I know what is the FCT and FGT version ?

 

Regards

 

ForgetItNet
Explorer II
July 24, 2025

I've tried it on both external and internal browser (and Edge, Chrome and Firefox). The FGT is on 7.4.8 and I've tried various different FortiClient but currently running 7.4

sharmar
Staff & Editor
Staff & Editor
July 29, 2025

Hello @ForgetItNet 

 

Ipsec + ext browser for SAML is only working in FGT 7.6.3+ so do your testing with internal browser only and Incase if you are using Ipsec over TCP then switch it with UDP because it will be stable in fct 7.4.4

 

ForgetItNet
Explorer II
July 29, 2025

Thanks Sharmar but i can only see up to 7.4.3 on FortiCloud to download ? Is 7.4.4 due out soon or should it already be available ?

sharmar
Staff & Editor
Staff & Editor
July 29, 2025

Hello @ForgetItNet 

7.4.4 is expected to be release by mid of next month so currently testing with 7.4.3 (Ipsec SAML + Embedded/internal browser) with UDP only a feasible solution. 

Thanks

ForgetItNet
Explorer II
December 19, 2025

Just as a note on this that the latest version of the Forticlient VPN only program 7.4.3 hotfix 1.8758 seems to have fixed this as long as you use the external browser option