Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Vanja98
New Contributor

FortiGate IKEv2 + SAML (Microsoft Entra ID) — “Firewall Authentication Failed” after MFA

Hello everyone,

 

We’re looking for guidance on an issue with FortiGate IKEv2 + SAML (Microsoft Entra ID). Below are the key details and symptoms.

 

Environment

Appliance: FortiGate 201G

FortiOS: v7.6.4 build3596 (Feature)

 

Symptoms

FortiClient opens the Microsoft Entra sign-in page and we receive the MFA push.

After approving MFA, the client returns “Firewall Authentication Failed.”

We are not able to access the ACS URL from the web. We get this page can’t be reached.

 

What we did
We followed the community article for Microsoft Entra ID SAML with FortiGate IPsec (IKEv2) and Fortinet’s official IPsec+SAML guide step by step, but the issue persists.

 

Firewall auth failed.jpg

 

Note: Before switching, we were using RADIUS for authentication and it was working.

 

Any advice on additional checks or known caveats with FortiOS 7.6.4 for IKEv2 + SAML would be appreciated. Thank you!

1 Solution
funkylicious
SuperUser
SuperUser

"jack of all trades, master of none"
2 REPLIES 2
funkylicious
SuperUser
SuperUser

"jack of all trades, master of none"
Vanja98

Thank you for the quick help—your guidance did the trick. We’re authenticating successfully now.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors