Skip to main content
DaveDavis
New Member
March 12, 2026
Question

SSO Login Authentication via KeyCloak with Microsoft Azure with FortiWeb

  • March 12, 2026
  • 8 replies
  • 342 views

Hello

We are using a FortiWeb cluster as a VM for our customer. The backend servers of our customer's customers are gradually being migrated to this FortiWeb cluster from a Sophos UTM 9. We also operate the Sophos UTM 9. The first backend servers are already running on the FortiWeb VM and access is successful. The challenge now is to migrate the backend servers that use SSO login via KeyCloak with Azure to the FortiWeb cluster. We have configured a test backend server for this purpose. Our customer  has configured KeyCloak (plain vanilla without any special configuartions) on his environment. We have configured the Azure parameters on our side in Azure. When accessing the test backend server via Sophos UTM 9, everything works without any problems. When accessing via FortiWeb,  I can authenticate and then it's pending. After round about 20 seconds comes '404 Not Found'. What did we overlook or configure incorrectly in the FortiWeb cluster configuration?

Thank you in advance for your input and help.


8 replies

AEK
SuperUser
SuperUser
March 12, 2026

Hi Dave

If after authentication it show 404 not found then is is probably redirecting to a wrong URL.

AEK
DaveDavis
DaveDavisAuthor
New Member
March 12, 2026

Hi AEK

Thank you for the input. I will check the redirects and hope there is the issue :).


DaveDavis
DaveDavisAuthor
New Member
March 16, 2026

Hi AEK

Unfortunately, checking the redirects and modifying various redirects did not resolve the issue. We currently suspect there is an additional check in the customer's application.

iamakk
Explorer
March 16, 2026

Fix the Redirect URI in Keycloak In your Keycloak client configuration (for the backend app), update the Valid Redirect URIs to the FortiWeb-facing URL:

 
 
https://<fortiweb-vip-or-fqdn>/auth/callback
https://<fortiweb-vip-or-fqdn>/*

Remove any Sophos UTM 9 addresses from this list.

DaveDavis
DaveDavisAuthor
New Member
March 17, 2026

Hi Ashish

Thank you for your input. I will check this.

Regards
Dave

DaveDavis
DaveDavisAuthor
New Member
April 9, 2026

Hello

I have an update:

We were able to resolve the issue. During a user’s SSO login, KeyCloak sends a query to itself using the application’s own public FQDN. As a result, the web application became both the WAF’s “backend” and the client at the same time. This led to asynchronous routing—the web app’s request went via the “internet” to the WAF’s first interface, but the response was sent back to the web app via the WAF’s second interface. As a result, the user could no longer log in via SSO.

As a solution, a reverse policy was implemented where the IPs of the backend servers respond using Source NAT. Now, it works properly.

Thanks everyone for the help.

filiaks1
Explorer III
June 10, 2026

So keycloak is not the actual Oauth AS server/SAML IdP but like SAML/OAuth proxy?  Or you mean you used KeyCloack with the Sophos UTM and now you want Azure with FortiWeb?

 

Maybe switch between SAML or Oauth OAuth authorization & OIDC authentication | FortiWeb 8.0.5 | Fortinet Document Library with Azure.

 

See also Single Sign On with Azure | FortiWeb 8.0.5 | Fortinet Document Library as the example is with SAML. Also nice debug article Troubleshooting Tip: Troubleshooting FortiWeb site publishing and Single Sign-On authentication issues | Community 

 

Outside of that open a support case if nothing helps and FortiAuthenticator could always be added between the Azure and FortiWeb if support can’t help as well.

 

Edit: for some reason I did not see the replies that this is resolved :) Nice!

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!