Created on
06-04-2025
04:37 AM
Edited on
06-23-2025
05:36 AM
By
Jean-Philippe_P
Description | This article describes an issue where users connecting to the IPsec remote VPN are not redirected to the SAML IDP for authentication. |
Scope | FortiGate. |
Solution |
When the user is trying to connect to the IPsec remote VPN, the IDP login page is not loading.
This issue can occur when the ike-saml-server is not configured on the interface on which the IPsec VPN is configured to listen.
Configure the ike-saml-server under the concerned interface. Enable the ike-saml-server under the interface using this command:
config system interface
Note: ike-saml-server can only be configured using CLI. Once the ike-saml-server is enabled on an interface, the FortiGate will start to listen for SAML authentication requests from FortiClient remote access IPsec VPN clients.
Debugs to be taken if any issue occurs:
diagnose debug application samld -1
To disable:
diagnose debug disable Technical Tip: How to configure Microsoft Entra ID SAML authentication for Dial-up IPsec VPN SAML-based authentication for FortiClient remote access dialup IPsec VPN clients |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.