Hello everyone,
I am using Fortigate 7.0.12 setting up SSL-VPN with Azure MFA using FortiClient mobile (7.2.0.0101) .
The setup works fine but gives a bad user experience for thousands of users on mobile (iOS and Android) by throwing an error webpage which is trying to reach 127.0.0.1:8020 (Error: This site can't be reached 127.0.0.1 refused to connect). I do not expect the FortiClient to be running anything on port 8020, or should it?
This error webpage is shown during the SAML authentication flow, and once it is promptly closed the connection is authenticated and browsing is normal. Has anyone found a workaround for this or some pointers to avoid this redirect error webpage?
Some info I found online about this redirect:
I was hoping I could change the 127.0.0.1 to something meaningful like a banner webpage instead. I can change the port using cli from 8020 to any port but not the hostname.
P.S: This 127.0.0.1:8020 error webpage does not occur when using the laptop/desktop FortiClient.
Solved! Go to Solution.
Can you test the behavior in FortiClient version 7.0.7 or 7.0.9 ? Also, whats the behavior when you change the redirect port to 0 ?
config vpn ssl settings
set saml-redirect-port 0
end
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.
Can you test the behavior in FortiClient version 7.0.7 or 7.0.9 ? Also, whats the behavior when you change the redirect port to 0 ?
config vpn ssl settings
set saml-redirect-port 0
end
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.
Hi Suraj,
That was pretty quick! Now client embeds the page within itself instead of creating an external pop up and the error is gone. Thanks a lot for your prompt reply.
P.S: The client is download directly from the google play store.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2023 Fortinet, Inc. All Rights Reserved.