Description | This article describes how to resolve the issue of 'Script Error' when trying to connect to SAML VPN. |
Scope | FortiClient v7.0.x and v7.2.x. |
Solution |
Sometimes after upgrading FortiClient to a newer version, the user may experience the below 'Script Error' when trying to connect to SAML VPN: (both SSL VPN and IPsec VPN).
Scenario 1: 'Access is denied' error.
To resolve this, there are a few options:
This setting will allow FortiClient to launch the default external web browser, and allow end users to log in using the web browser instead of the FortiClient embedded web browser.
Start -> Edit Group Policy -> Computer Configuration -> Administrative Templates -> Windows Components -> Internet Explorer -> Internet Control Panel -> Security Page -> Internet Zone:
Once this option is set to enable or not configured, the 'Script Error' message will no longer prompt.
Note that when applying option no.3, the SAML VPN behavior will follow as described in the SSL VPN docs guide.
Start -> Type: Internet Option -> Security tab -> Select Trusted sites -> Add the remote VPN gateway FQDN or IP -> OK.
Scenario 2: 'Invalid character' error.
To resolve this, there are a few options:
The configuration will look like this:
<use_gui_saml_auth>1</use_gui_saml_auth>
A more detailed explanation and behavior when the test machine is joined to Entra ID domain is provided in the XML Reference Guide. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.