FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
ssanga
Staff & Editor
Staff & Editor
Article Id 268564
Description This article describes the process for setting up automatic redirection of the SSL VPN web portal URL to the SAML SSO login page, eliminating the requirement to manually select the Single Sign-On button.
Scope FortiGate.
Solution

The automatic redirection of SSL VPN web access to the SAML SSO login page is accomplished in the following scenarios.

Solution 1:
Ensure that Authentication/portal mapping rules do not have any non-SAML user groups associated with that particular SSL VPN web portal url/realm. Only in such cases, access to the SSL VPN URL will seamlessly redirect to the SAML SSO login page, eliminating the need to manually click the Single Sign-On button. Additionally, make sure the Firewall policies for SSL VPN do not have any non-SAML user groups associated with them.  

 

Select VPN -> SSL-VPN Settings -> Authentication/Portal Mapping, create or edit

 

PIC1.png

 

Solution 2:

In cases where SAML and non-SAML user groups are configured under the Authentication/Portal Mapping rules (ex: SAML user group, local user group, and remote LDAP/RADIUS user groups) for a particular SSL VPN web portal url/realm,

Create a new realm and associate only SAML user groups to this realm under the Authentication/Portal Mapping rules.

Upon accessing the SSLVPN web portal using the new URL generated from the new realm, the user will instantly redirect to the SAML SSO login portal.

Select VPN -> SSL-VPN Settings -> Authentication/Portal Mapping and selectcreate or edit:

PIC2.png

Related articles:

Technical Tip: How to fix crashing SAML daemon
Technical Tip: How to read SAML Debug output

Technical Tip: A basic explanation of SAML authentication

Technical Tip: Configuring SAML SSO login for FortiGate administrators with Entra ID acting as SAML ...

Technical Tip: Configuring SAML SSO login for FortiGate Admin Web GUI Access with JumpCloud acting a...
Technical Tip: Configuring SAML SSO login for FortiGate administrators with Okta acting as SAML IdP

Technical Tip: Configuring SAML on FortiGate displays the error 'Cannot change this setting in SP wh...

Technical Tip: Set up SAML admin LDAP login on FortiGate (SP) with FortiAuthenticator (IDP)

Technical Tip: Configuring FortiGate SSO Administrators with ADFS as SAML IdP
Technical Tip: Using single Azure Enterprise Application for multiple SAML Service Providers (SPs) f...

Troubleshooting Tip: Admin authentication with SAML SSO breaks after upgrade to firmware 7.4.1

Technical Tip: Configure SAML SSO for WiFi SSID over Captive Portal with Azure AD as IdP

Technical Tip: Configuring SAML SSO login for FortiGate administrators with Entra ID acting as SAML ...