Skip to main content
dydy77
Explorer II
April 28, 2025
Question

SSLVPN to IPSEC with multi realms

  • April 28, 2025
  • 8 replies
  • 3071 views

Hello everybody

In order to anticipate futur end of life of VPNSSL function, i try to make working VPN acces by IPSEC.

 

Actually :

 

1 fortigate 100f

1 wan fiber

2 SSO connexions, for 2 different  Microsoft tenants

2 VPN SSL REALMS

2 SSL PORTAL in tunnel mode

In SSL Settings, i use SSL portal mapping

 

Capture d’écran 2025-04-28 151822.png

 

In forticlient 2 configurations, one per realms, both pointing to the same wan ip/port, juste realms is different.

 

I would like to make the same configuration but with IPSEC.

 

 

nowday i make working IPSEC with SAML, but only for 1 tenant.

following this guide : https://docs.fortinet.com/document/fortigate/7.4.7/administration-guide/951346/saml-based-authentication-for-forticlient-remote-access-dialup-ipsec-vpn-clients#IKEv2

 

I don't know how to do this, as my wan link is configured to listen and transfer to a single SSO configuration (saml server).

config system global     set auth-ike-saml-port <integer> end

config system interface     edit <name>         set ike-saml-server <saml_server>     next end

 

Thanks for your futur help

 

8 replies

Stephen_G
Staff & Editor
Staff & Editor
May 2, 2025

Hello,

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.

 

If anyone viewing this topic has any knowledge on this, I encourage you to reply.

 

Thanks,

Stephen_G - Fortinet Community Team
Stephen_G
Staff & Editor
Staff & Editor
May 6, 2025

Hello,

 

We are still looking for an answer to your question.

 

We will come back to you ASAP.

Once more, if anyone has any advice, please feel free to share it.

 

Thanks,

Stephen_G - Fortinet Community Team
Toshi_Esumi
SuperUser
SuperUser
May 12, 2025

As far as I know SSL VPN wouldn't go away any time soon if your FGT is 100F, a rack-mountable model with 7.6GB memory. Two of our customers are using 100F for their HQ with SSL VPN, and we're assuring them they can keep using it.

First I have to tell you I never made, or even tried, implementing Entra ID groups with dialup IPsec VPN on any FGTs. So this is just based on my on-line research.

You already made Entra ID work for dialup ipsec over SAML so you already cleared this part. But this is what I could find in FTNT's KBs:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-configure-Microsoft-Entra-ID-SAML/ta-p/307457

For the multiple groups on the Entra ID side, it's a question to Microsoft and I couldn't find any FTNT KB about that. So you have to figure it out by yourself. Or you might be able to ask MS Azure support for how to.

But I found a third party article how to incorporation groups over SAML on the FGT side by policies:
https://www.andrewtravis.com/blog/ipsec-vpn-with-saml
This guy uses FortiAuthenticator(FAC) as IdP, not Entra ID, and set groups there. But I'm assuming the FGT side should be similar if not identical.

So try combining those and let all the rest know how it went. If you could figure this out, this thread would become one of those KB equivalent articles helping all other FGT users, which I'm sure I would give you kudos.

Good luck.

Toshi

dydy77
dydy77Author
Explorer II
May 12, 2025

Thanks for our help.

 

The main problem is with 2 realms (2 tenants).

Just with one like your article, it is working fine, and i validate than groups in policy can be use to filter users acces.

This point is good and replacing weel SSL solution.

 

In the initial SSL case :

  1. User connexion with forticlient by select realms
  2. Fortigate is waiting on SSL port
  3. Fortigate redirects the connection to the correct SAML (Microsoft tenant) using the realms association and validates the connection.
  4. Groups in the policy end user access validation.
  5. All is OK

 

In the new IPSEC case :

  1. User connexion with forticlient (no realms possibility as i know)
  2. Fortigate is waiting on auth-ike-saml-port
  3. Fortigate's wan link is connected to a single SAML connection ( ike-saml-server), so Fortigate doesn't check which tenant needs to be contacted..... With 2 wan links, I think (not try) it's possible (one per tenant, each wan link configured to a different ike-saml server).

 

I don't know if my request (problem) is clear, or if i don't understand somethings.... but with all informations i knows, i don't see how to make working that in my case.

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!