Skip to main content
echo
Explorer II
May 29, 2014
Question

VPN+SSO possible?

  • May 29, 2014
  • 5 replies
  • 22128 views
Hello! I am searching for possibilities to configure client VPN with SSO. So far I don' t understand if this is possible at all, can' t find any example from Fortinet docs. I tried to start doing client VPN and use Radius SSO group, but just got stuck somewhere: the SSO user group that I defined couldn' t be selected for phase1-interface. In addition to that, I found fortios-handbook-50.pdf from http://docs.fortinet.com/d/fortigate-fortios-handbook which has such information: --- Page 482: The Fortinet Single Sign On (FSSO) agent enables FortiGate units to authenticate these network users for security policy or VPN access without asking them again for their username and password. /---/ The FSSO user groups that you created are used in security policies and VPN configurations to provide access to different services and resources. Page 508: FSSO user groups cannot have SSL VPN or dialup IPsec VPN access. --- Does that mean that SSO can' t be used for VPN or what? Cookbook 507 also didn' t have any such recipe. I have set up IPSEC and SSL VPNs for clients (for FortiClient and Shrew) with AD authentication (LDAP and Radius) and local authentication several times so I have that knowledge to go on with, but I have no experience with SSO, hence my noob question :)

    5 replies

    Dipen
    New Member
    June 23, 2014
    If you want to use AD Authentication with SSL-VPN then LDAP authentication will works for you. FSSO I have not heard to work with SSL-VPN. Please note that SSL-VPN is for remote users who of course will not be communicating with AD Server.
    PMD
    New Member
    June 29, 2014
    FSSO doesnt work with SSL VPN as Dipen informed you can intergrate authentication with LDAP.
    rwpatterson
    New Member
    June 29, 2014
    Think about it the logical way. For SSO to work, a user needs to be authenticated first, then their login credentials are passed from one system to the next. Outside users are not authenticated before they attempt to log into the firewall. You can user the same login database (AD) for authentication for both incoming (via LDAP) and outgoing (via FSAE/FSSO). Configuration for each is vastly different, but as far as I am aware, there is no Single Sign On for incoming connections.
    echo
    echoAuthor
    Explorer II
    July 11, 2014
    OK, thank you all, I see that these two things seem to have different purposes.
    albertommo
    Visitor III
    January 3, 2023

    Maybe I'm too late, but I've heard about VPN SSL SSO using SAML so, you can configure it to use it with Azure SSO or FortiAuthenticator as IdP. Check this link https://community.fortinet.com/t5/FortiGate/Technical-Tip-Create-SSL-VPN-with-Azure-SAML-SSO-Authentication/ta-p/200812

    aahmadzada
    Staff
    Staff
    June 6, 2023