Created on
09-02-2025
02:11 AM
Edited on
09-11-2025
07:01 AM
By
Stephen_G
Description | This article describes why the SAML authentication port changes after the FortiGate reboot. |
Scope | FortiClient v7.2.0, FortiGate v7.6.3 and v7.4.8, SAML. |
Solution |
Since v7.2.0, SAML-based authentication for FortiClient remote access dial-up IPsec VPN clients is supported, and this feature requires FortiClient v7.2.4 and supports only IKEv2.
The change can be made only by CLI as follows:
On v7.6.3 and v7.4.8, there is an issue that changes the port customized (10443) to the default port (1001) after the FortiGate reboot, and it is possible to check from the below command after the device initiates:
As a workaround, it is necessary to change to another port than 10443, like 11443, as shown in the example:
It will be necessary to open a case with the TAC support in case the issue remains.
Related documents: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.