Created on 11-20-2024 06:17 AM Edited on 11-24-2024 06:00 AM By Jean-Philippe_P
Description | This article describes how to troubleshoot the error 'Wrong Credentials' when using Azure SAML SSO with IPsec Dial-up VPN. |
Scope | FortiGate. |
Solution |
When connecting to IPsec Dial-up VPN using Azure SAML SSO, the error 'wrong credentials' was observed.
Running samld and ike debug on FortiGate, the following output is seen: FGT_1 # diagnose debug reset FGT_1# diagnose debug application samld -1 8010100020300002801010000800B0001000C00040001518080010007800E008080030001800200028004000500000028 02010000800B0001000C00040001518080010007800E01008003000180020004800400050A0000C4B10D67F5C6342E9E4 BACCE8E8CF7D2CF2DAC0DA0E5909C0741DE6578D5D24A0C53D4ACFABCBF35EEEAE747E959E68A538ABEB906455F752934 666B389DD4CEC0E6972927B7231E95424E2B37D9E30C24ADBF4B60E3A53B72F0AC75E785A8581DDF1DE02E6DA057FAF7C 1B2454B5DAF844155AA927CB4EA6690C0E6AF4B2F3AEA0D8DFC1B25EE4134714A8F42F57BB80089614B5C940A7314EBF0 E25CF289B10469433E44BCE611F8F31355481114FE9C920FA693B500CC66EEEA37AC62A4A95905000014B916D5A8F96CD 3537B35DF50B92967800D00000C01000000C0A802270D00001412F5F28C457168A9702D9FE274CC01000D0000144A131C 81070358455C5728F20E95452F0D000014CD60464335DF21F87CFDB2FC68B6A4480D00001490CB80913EBB696E086381B 5EC427B1F0D00000C09002689DFD6B7120D000014AFCAD71368A1F1C96B8696FC775701000D0000144C53427B6D465D1B 337BB755A37A7FEF00000014B4F01CA951E9DA8D0BAFBBD34AD3044E SAML is sending the correct username. However, phase 1 is matched to the wrong tunnel. This is because there are multiple dial-up tunnels configured on the same gateway. To avoid this, use the 'peer id' setting on FortiGate and the 'local id' setting on FortiClient to match the right tunnel.
config vpn ipsec phase1-interface edit <phase1-name> set peertype one set peerid <CustomerPeerIdString>
The <CustomerPeerIdString> should be used as a Local ID on FortiClient remote access profiles.
Related article: How to use Peer IDs to select an IPSec di... - Fortinet Community |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.