FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Rajneesh
Staff
Staff
Article Id 365592
Description

This article describes the issue where user is unable to call multiple SAML groups belonging to multiple IDPs.

Scope FortiGate.
Solution

From the attached image it can be noted that when another SAML group is being used in the firewall policy it is giving the following error:

 

In the GUI, the error is as follows:

 

-651: Input value is invalid.

 

In the CLI, the error is as follows:

 

SAML user number is more than one.

object set operator error, -651 discard the setting

Command fail. Return code 1

 

SSO.jpg

 

If the SAML groups will belong to different IDPs, this error will appear.

Starting with FortiOS 6.4.6, 7.0.1, and 7.2.0, although it is possible to add multiple SAML groups to a single firewall policy, but the SAML groups must reference the same SAML IDP server not to the different IDP server.