Description | This article describes how to resolve the '403 Forbidden error' when trying to connect to SAML IPsec VPN with DUO MFA |
Scope | FortiClient v7.2.9, v7.2.10, v7.4.0 and above |
Solution |
When connecting to a SAML IPsec VPN with DUO MFA, after inputting SAML username + password + DUO MFA, FortiClient Windows shows '403 Forbidden error' and is unable to proceed:
With an EMS subscription:
This is due to incorrect [After Logon SAML Authentication Framework] settings.
Note: Without an EMS subscription, enabling the 'Use external browser as user-agent for saml user authentication' option also resolves this error. If the issue is on v7.2.9 or v7.2.10, the solution is to upgrade to v7.4 to use the external browser option.
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.