FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
vermap
Staff
Staff
Article Id 382546
Description This article describes the troubleshooting steps when the captive portal with SAML authentication with the WiFi users failed to load with the error 'Firewall Authentication Failed'.
Scope FortiGate.
Solution

When connecting to the WiFi SSID and trying to access the captive portal page with SAML authentication, the page gets redirected but gives the error 'Firewall Authentication Failed':

 

image.jpg

 

This happens because of the mismatch between the User group ID in FortiGate and Azure. Make sure the group ID is the same on FortiGate and Azure as shown below

 

Capture-12.PNG

 

Alternatively, it can also be edited through CLI

 

Capture-210.PNG

 

Related documents:

Captive portal authentication using SAML credentials 

Technical Tip: Configure SAML SSO for WiFi SSID over Captive Portal with Azure AD as IdP