Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rewt
New Contributor

FortiClient 7.4.2 and SSL VPN + Azure SAML not working with internal browser, works with external

So I have been struggling for a bit to figure out why my SSL VPN configuration with Azure SAML doesn't work with FortiClient 7.4.2.  Older FortiClient version seem to not have this issue.  The most telling thing I see in the server debug log is:

 

[394:root:5b4b]SSL state:fatal decode error (x)
SSL state:fatal decode error (x)

 

then:

 

[394:root:5b4c]saml login [394:23372] SAML_ERROR: Error occurred during remote login 'could not found corresponding saml session (101)'

 

If I use the option in FortiClient "Use external browser as user-agent for saml user authentication", I get no such error and everything works just fine.

 

Any guesses as to what might be causing this issue?  When I searched on this issue, I only found similar issues  but where the opposite was true - using external browser for saml user authentication did not work as expected.

 

I am a little reluctant to upgrade the users to such an unstable situation.

10 REPLIES 10
idumancic
Staff
Staff

To check:
Same error message in this KB

SAML_ERROR: Error occurred during remote login 'could not found corresponding saml session (101)'

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Unable-to-login-on-SSL-VPN-48-using-...

idumancic
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors