Hello everyone,
We’re looking for guidance on an issue with FortiGate IKEv2 + SAML (Microsoft Entra ID). Below are the key details and symptoms.
Environment
Appliance: FortiGate 201G
FortiOS: v7.6.4 build3596 (Feature)
Symptoms
FortiClient opens the Microsoft Entra sign-in page and we receive the MFA push.
After approving MFA, the client returns “Firewall Authentication Failed.”
We are not able to access the ACS URL from the web. We get this page can’t be reached.
What we did
We followed the community article for Microsoft Entra ID SAML with FortiGate IPsec (IKEv2) and Fortinet’s official IPsec+SAML guide step by step, but the issue persists.
Note: Before switching, we were using RADIUS for authentication and it was working.
Any advice on additional checks or known caveats with FortiOS 7.6.4 for IKEv2 + SAML would be appreciated. Thank you!
Solved! Go to Solution.
hi,
have a look at https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-SAML-Authentication-fails-after-firm...
hi,
have a look at https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-SAML-Authentication-fails-after-firm...
Thank you for the quick help—your guidance did the trick. We’re authenticating successfully now.
User | Count |
---|---|
2609 | |
1390 | |
804 | |
664 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.