FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
kjiye
Staff
Staff
Article Id 239520
Description This article describes how to configure SSL VPN users using SAML(okta) with local AD for authentication and authorization.
Scope FortiGate
Solution

Related article:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configuring-SAML-SSO-login-for-SSL-VPN-web...

 

Configure Okta and Active Directory integration.

 

- Create a new Directory integration:

1) Go to Directory -> Directory Integrations -> 'Add Active Directory'.

 

kjiye_2-1670913457703.png

 

2) Select 'Set Up Active Directory'.

 

Check the Installation requirements before selecting the button.

 

kjiye_3-1670913491626.png

 

3) Select 'Download Agent'.

After then, it is possible to check item B with the Okta Organization URL and an administrator account on the page.

Until the file is installed on the AD server, the message 'Waiting for the agent installer to update this page' will be displayed continuously.

 

kjiye_4-1670913754903.png

 

4) Install the Okta AD Agent.

- Input the domain name, proxy(if there is one) setting -> Next.

- Enter Organization URL.

Item B shown in number 3 contains the Organization URL.

 

kjiye_7-1670914835356.png

 

- When the 'Sign into Okta with Administrative User Account' page is displayed, log in to Okta and select 'Allow Access' button.

 

kjiye_8-1670915218557.png

 

- It is possible to check the pop-up page with 'Active Directory agent started!'.

 

5) Select the Organizational Units(OU) and username format.

 

kjiye_10-1670915561789.png

 

6) Set the attribute value to be linked with Okta.

7) Done.

 

- Import user information from AD to Okta.

1) under Directory -> Directory Integrations -> Select the AD created in the previous step.

2) Import -> 'Import Now'.

 

kjiye_1-1670916933806.png

 

3) When importing a user for the first time, select Full import to import.

 

kjiye_3-1670917060489.png

 

4) Select the user, and confirm.

 

kjiye_5-1670917415941.png

 

5) Check is the account is activated in Directory -> People.

 

kjiye_9-1670919400819.png

 

- Assign the imported user ID to the okta application.

 

1) Select the OKTA application.

 

 
kjiye_7-1670918019696.png

 

2) Go to Assignments -> Assign -> Assign to People(Or Groups).

 

kjiye_8-1670918194578.png

 

3) Assign the user ID who will use SSL VPN.

 

- Login with AD ID and okta authentication (In this article,  web mode SSL VPN has been used.).

 

1) Select the Single Sign-on.

 

kjiye_11-1670919942555.png

 

2) Enter the AD credentials.

 

kjiye_12-1670920155506.png

 

3) Done!

 

kjiye_13-1670920357002.png
Contributors