SSLVPN SAML with Google IDP
SSLVPN SAML is working in 6.4 with Google IDP
config user saml edit "Google" set entity-id "https://gateway.xxxxx.com/remote/saml/metadata" set single-sign-on-url "https://gateway.xxxxx.com/remote/saml/login" set single-logout-url "https://gateway.xxxxx.com/remote/logout" set idp-entity-id "https://accounts.google.com/o/saml2?idpid=C011xxxxx" set idp-single-sign-on-url "https://accounts.google.com/o/saml2/idp?idpid=C011xxxxx" set idp-single-logout-url "https://accounts.google.com/o/saml2/idp?idpid=C011xxxxx" set idp-cert "REMOTE_Cert_1" set user-name "Email" set group-name "Memberof" next end
Make sure you have local users with full email address for user name in Fortigate.
Google setup is simple.
ACS
https://gateway.XXXXX.com/remote/saml/login
Entity ID
https://gateway.XXXXX.com/remote/saml/metadata
Start URL
https://gateway.XXXXX.com/remote/saml/login
NameID - Basic Info - Primary Email
Name IF Format - Email
