Description |
This article describes the case when it is desired to access the VPN using web mode but it is showing 400 or 403 Forbidden error while SSL VPN is configured with SAML authentication. |
Scope | FortiGate. |
Solution |
SSL VPN web mode gets the error below when configured with SAML authentication.
Forbidden You don't have permission to access /remote/saml/start on this server.
Additionally, a 400 Bad Request error was encountered while trying to use an ErrorDocument to handle the request.
Forbidden
[865:root:219]SSL state:fatal decode error (192.168.141.179) [864:root:21b]Destroy sconn 0x7f76c36800, connSize=0. (root)
config vpn ssl web portal edit "full-access" set web-mode enable
Warning: Note that the legacy SSL VPN web mode feature is disabled by the global sslvpn-web-mode setting.
Enable the web-mode globally: config sys global set sslvpn-web-mode enable end
The web mode of SSL VPN should work as expected after enabling web-mode for specific portals. To enable the web mode for specific portals run the command as shown in step 1.
If the issue persists, contact the TAC team. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.