Created on
11-11-2024
09:49 AM
Edited on
11-27-2025
10:10 PM
By
Jean-Philippe_P
| Description | This article describes how to resolve the '403 Forbidden error' when trying to connect to SAML IPsec VPN with DUO MFA |
| Scope | FortiClient v7.2.9, v7.2.10, v7.4.0 and above |
| Solution |
When connecting to a SAML IPsec VPN with DUO MFA, after inputting SAML username + password + DUO MFA, FortiClient Windows shows '403 Forbidden error' and is unable to proceed:
With FortiClient EMS subscription:
This is due to incorrect [After Logon SAML Authentication Framework] settings.
Note: Without a FortiClient EMS subscription, enabling the 'Use external browser as user-agent for SAML user authentication' option also resolves this error. If the issue is on v7.2.9 or v7.2.10, the solution is to upgrade to v7.4 to use the external browser option. Dialup IPsec VPN with SAML using an external browser for authentication is supported starting from FortiOS v7.6.1, FortiClient (Windows) and (macOS) v7.2.5 and v7.4.1, and FortiClient (Linux) 7.4.3. If the FortiOS version is below this version, disable the 'Use external browser as user-agent for saml user authentication' option in the FortiClient. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.