Description |
This article describes the troubleshooting steps when connecting to an IPsec VPN with SAML-based authentication from FortiClient, where FortiClient is stuck in a connecting state even after entering valid credentials. |
Scope | FortiGate. |
Solution |
When connecting to the IPsec remote access VPN, FortiClient prompts the Single Sign-On (SSO) login page. After successful authentication, the FortiClient may sometimes remain connected.
diagnose debug disable
If the SSO group is configured in both places, remove it from one configuration and test the VPN connection again.
If the issue persists, collect the following logs and open a ticket with TAC support at the Fortinet Support Portal.
Run the following commands on the FortiGate CLI
diagnose debug reset Replicate the issue by connecting to the VPN from the FortiClient. After issue replication, please run the following commands to stop the debug. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.