Skip to main content
hamil
New Member
February 16, 2026
Question

Mixed Local and SAML users with IPSEC Dialup

  • February 16, 2026
  • 1 reply
  • 184 views

Hello all, in the context of migration from SSL-VPN I am facing the following problem.

Many of our client deployments include a mix of SAML users (dial up for company users) and locally defined users (contractors for instance)

In SSL-VPN it was as simple as enabling or disabling the SSO checkbox in Forticlient. If SSO was enabled, the connection flow would go through SAML authentication, and if disabled it would connect directly using local users.

I tried this with IPSEC dial up configuration, and unchecking SSO in Forticlient has no effect, it will always ask for SAML authentication.

Anyone tried this and got success? Any workaround?

1 reply

funkylicious
SuperUser
SuperUser
February 16, 2026
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!