Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Remsondu1
New Contributor III

Configure Fortinet ZTNA Application Gateway with SAML and MFA using FortiAuthenticator

Configure Fortinet ZTNA Application Gateway with SAML and MFA using FortiAuthenticator 

 

In this hands-on tutorial, you'll learn how to configure Fortinet’s ZTNA Application Gateway with SAML-based authentication and Multi-Factor Authentication (MFA) using FortiAuthenticator. :rocket: What you'll learn: Step-by-step setup of ZTNA Application Gateway on FortiGate Integration of FortiAuthenticator as a SAML Identity Provider Enabling MFA for secure remote access Creating secure access policies for remote users Testing and troubleshooting authentication flows

https://youtu.be/zngSdBCOPyY

 

Bowale Oyenuga
Bowale Oyenuga
1 REPLY 1
Durga_Ashwath

Hi Team,

To configure a Fortinet ZTNA application gateway with SAML and MFA using FortiAuthenticator, follow these steps:

1. Set Up FortiAuthenticator as SAML IdP:
- Access the FortiAuthenticator management interface.
- Navigate to the SAML IdP settings and configure the necessary parameters to act as the Identity Provider (IdP).

2. Configure SAML Authentication on FortiGate:
- Log in to the FortiGate management interface.
- Go to the ZTNA configuration section and select the application gateway settings.
- Enable SAML authentication and input the IdP details from FortiAuthenticator.

3. Enable Multi-Factor Authentication (MFA):
- On FortiAuthenticator, ensure that MFA is enabled for the user accounts that will be accessing the ZTNA resources.
- Configure the MFA settings, such as FortiToken, to be used during the authentication process.

4. Connect FortiGate to FortiAuthenticator:
- Ensure that the FortiGate EMS fabric connector is successfully connected to FortiAuthenticator.
- Verify the connection and ensure that the FortiGate can communicate with FortiAuthenticator for authentication requests.

5. Test the Configuration:
- Attempt to access the ZTNA-protected resources using a remote user account.
- Ensure that the user is prompted for SAML authentication and MFA verification.
- Verify that access is granted only after successful authentication and MFA verification.

Please do follow the below article:
https://docs.fortinet.com/document/fortigate/7.6.0/administration-guide/259754/ztna-application-gate...
https://docs.fortinet.com/document/fortigate/7.6.0/administration-guide/751123/ztna-configuration-ex...
https://community.fortinet.com/t5/Support-Forum/ZTNA-with-2FA/td-p/215662
https://docs.fortinet.com/document/fortigate/7.6.3/administration-guide/461532/ztna-application-gate...

Thank you.

Regards,
Durga A




 

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors