FortiAuthenticator
FortiAuthenticator provides centralized authentication services for the Fortinet Security Fabric including multi-factor authentication, single sign-on services, certificate management, and guest management.
jcastellanos
Staff
Staff
Article Id 374010

 

Description

This article describes how misconfiguration of the Authorized Server IP of Facebook API can lead to social authentication failure.

Scope FortiAuthenticator v6.6.x.
Solution

Admin is configuring Facebook Social Login as described in Documentation. See social-wifi-captive-portal-with-fortiauthenticator-facebook for more information.

 

When Admin tries to log in using Facebook Social Login, authentication will fail and return to the same login page:

 

portalsendagain.png

 

It is possible to find a log message in the FortiAuthenticator:

 

errorlog.png

 

date=2025-02-01 time=21:53:05+0000 oid=888 logid=20603 cat="Event" subcat="Authentication" level="error" nas="" action="Login" status="Failed" msg="Social authentication failed. Response from facebook-gp: Authentication process canceled" user=""


It could be related to the configuration of the Authorized Server IP in the Facebook App section.

 

facebook api.png

 

In this section, the Public IP address that FortiAuthenticator will use to reach the Facebook API is defined. Consider configuring the translated IP address in case FortiAuthenticator is behind of NAT device.