Description | This article discusses how Authentication Keepalive is causing IPsec VPN with SAML Authentication to fail. |
Scope | FortiGate. |
Solution |
When enabling Authentication KeepAlive causes the IPsec VPN with SAML not to connect.
FortiClient initiated SAML authentication: [authd_local_saml_auth:5778]: SAML login with UID '2D56XXXXXXXXXXX30A4D3DA0E'. End user provided SSO/SAML credentials, which were received by FortiGate. samld_send_common_reply [95]: Attr: 10, 43, 'username' 'adimailig@fortinet-us.com'
[authd_http_prepare_javascript_redir:3942]: https://54.252.41.X:9443/keepalive?07060802060e090d [132] __saml_auth_cache_push-Auth cache created, user='2D56XXXXXXXXXXX30A4D3DA0E', SAML_server='IPSEC_SAML', vfid=0
config system global set auth-keepalive disable end
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.