Afternoon all,
I have a Fortigate 91G running on 7.4.7 presently as it's still running SSO SSL VPN, linked to EntraID for SAML.
With the SSL VPN being deprecated on later versions for this unit, we are trying to migrate to dial-in IPSec VPN but am being given the restriction of using certificates instead of the PSK to implement this.
So, is it possible to implement a dial-in IPSec that links to EntraID for SAML, but doesn't require the PSK, and allows me to use a certificate instead?
I have so far managed to get the Forticlient to connect and you see the Phase1/Phase2 tunnels on Status/Networks/IPSec but no traffic fails to flow over it. Forticlient is stuck during the connection phase as well, not displaying the counter and details like it would when connected successfully.
Feels like there's a disconnect between the PKI configured and SAML authentication systems, which may be the issue.
Sanitised Phase 1 configuration in use
---------------------------------
Ignore this (I can't find the delete option) but it DOES work with the new version of the VPN only program 7.4.3 hotfix 1.8758, it was a setting that I hadn't changed since trying to fix it last time.
| User | Count |
|---|---|
| 2872 | |
| 1446 | |
| 840 | |
| 821 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.