Created on
10-07-2024
06:56 AM
Edited on
10-07-2024
07:00 AM
By
Jean-Philippe_P
| Description | This article describes the configuration of SSO admin access to FIPS-CC Certified FortiGate using FortiAuthenticator as IDP. |
| Scope | All FortiOS and FortiAuthenticator versions Including FIPS certified FortiOS versions. |
| Solution |
All the IP addresses used are for demonstration purposes only. FortiAuthenticator configuration:
IDP Certificate.
FortiGate SSO Configuration: FortiGate FIPS-CC enabled: config system fips-cc set status enable end
FIPS-CC will be enabled only from Console access.
FortiGate Interface: WAN1 connecting to the FortiAuthenticator.
FortiGate SAML Configuration:
CLI Reference:
config system saml
Here 'FAC' is the Certificate imported from FortiAuthenticator to FortiGate as a Remote Certificate:
Configure the SSO Admin on FortiGate:
Final Result:
This configuration can also be used for Non-FIPS Certified FortiOS. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.