Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
UdaM
New Contributor III

FortiSASE ZTNA Shortcuts config with SMAL Authentication

Try to config ZTNA Shortcuts on SASE end point already integrated with Entra ID. Need clarify 

 

config user saml
edit "saml_ztna"
set cert "Fortinet_CA_SSL"
set entity-id "https://fgt9.myqalab.local:7831/samlap"
set single-sign-on-url "https://fgt9.myqalab.local:7831/XX/YY/ZZ/saml/login/"
set single-logout-url "https://fgt9.myqalab.local:7831/XX/YY/ZZ/saml/logout/"
set idp-entity-id "http://MYQALAB.LOCAL/adfs/services/trust"
set idp-single-sign-on-url "https://myqalab.local/adfs/ls"
set idp-single-logout-url "https://myqalab.local/adfs/ls"
set idp-cert "REMOTE_Cert_4"
set digest-method sha256
set adfs-claim enable
set user-claim-type upn
set group-claim-type group-sid
next
end
 

The entity-id single-sign-on and single-logout URLs from SASE and  idp URLs from SMAL authenticator ( In My case it's Entra ID ) 

 

i follow below guidelines

 

https://docs.fortinet.com/document/fortisase/latest/spa-using-ztna-deployment-guide/976373/configuri... 

 

ZTNA proxy access with SAML authentication example   

 

 

~UdaM~
~UdaM~
2 Solutions
UdaM
New Contributor III

HI @sjoshi 

 

Thank you for your replay ,

My idp is AZURE. How about entity-id single-sign-on and single-logout URLs is it from SASE or FG HUB?

 

 

 

~UdaM~

View solution in original post

~UdaM~
sjoshi

Hi ,

 

In the case of ZTNA the SAML info must be validated betn hub fgt and the azure idp.

Here sase is just for ems for sync tag on the FCT endpoint and the FGT

If you have found a solution, please like and accept it to make it easily accessible to others.
Fortinet Certified Expert (FCX) | #NSE8-003459
Salon Raj Joshi

View solution in original post

3 REPLIES 3
sjoshi
Staff
Staff

Hi UdaM,

As per your notes you are trying to setup ZTNA access proxy using HUB FGT with SAML auth using SASE for ems.
what is the idp you are using? Azure or FAC?
the url that you need to configure idp-single-sign-on-url & idp-single-logout-url should be exactly matching with what is present on the IDP side.

If you have found a solution, please like and accept it to make it easily accessible to others.
Fortinet Certified Expert (FCX) | #NSE8-003459
Salon Raj Joshi
UdaM
New Contributor III

HI @sjoshi 

 

Thank you for your replay ,

My idp is AZURE. How about entity-id single-sign-on and single-logout URLs is it from SASE or FG HUB?

 

 

 

~UdaM~
~UdaM~
sjoshi

Hi ,

 

In the case of ZTNA the SAML info must be validated betn hub fgt and the azure idp.

Here sase is just for ems for sync tag on the FCT endpoint and the FGT

If you have found a solution, please like and accept it to make it easily accessible to others.
Fortinet Certified Expert (FCX) | #NSE8-003459
Salon Raj Joshi
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors