Dear All,
i was trying to configuring SAML SSO login for ssl vpn with azure ad, i followed below command in fortigate and when i type next, it popup entity-id is empty, and i also have below question in green, any help would be appreicated
FortiGate-100F (Azure-name) # next
node_check_object fail! for entity-id is empty.
Attribute 'entity-id' MUST be set.
Command fail. Return code 1
piaakit
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi @piaakit1210 ,
I believe you need to import the SAML IdP Certificate from the Azure.
And yes that entity-id is set under basic SAML configuration.
Have a look at this guide as it may help with your configuration :
Hi,
As DBU confirmed you need to download the certificate, please review also the following article:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Create-SSL-VPN-with-Azure-SAML-SSO-Authent...
Here you can also find a video :
Configure Fortigate SSL VPN to use Azure AD as SAML IDP (MFA / Conditional Access)
https://www.youtube.com/watch?v=nDH2wvveLrI
-BR-
Hi @piaakit1210,
Did you set the command
config user saml
set entity-id
For the "set cert" command, you can the cert assign in SLS VPN setting and the "set idp-entity-id" command is "Azure AD identifier" which be found under step 4 in Azure "Set up FortiGate SSL VPN" not the SAML config.
Regards,
Minh
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1698 | |
1092 | |
752 | |
446 | |
228 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.