Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Matager
New Contributor

Fortigate SAML SSO login with Azure Entra ID admin account

Hi,
I am trying to integrate azure entra id into fortigate, the objective is to login into the fortigate using azure admin account.
All worked well but facing one problem. When i click SSO login the page redirects me to the microsoft login and when i enter my credentials it gives error "Reply URL mismatch", however i have verified that all URLs from Fortigate SP as same in the Azure SAML settings.

 

Guide i followed: 
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configuring-SAML-SSO-login-for-FortiGate/t...

5 REPLIES 5
tayorv
New Contributor

config system saml

user saml is for sslvpn

... and set your digest-method to sha256 for good measure :)

https://tutuapp.uno/
rbraha
Staff
Staff

Hi @Matager 

 

Can you please send some screenshot of configuration on FGT CLI and configuration on Azure side.

 

config user saml

show

 

Matager
New Contributor

Please note that we are not trying to use azure for SSL-VPn, we are trying to login into the firewall using azure admin account.
Below is the output.
AFW1-FG-80F # config user saml

AFW1-FG-80F (saml) # show
config user saml
end

AFW1-FG-80F (saml) #

rbraha
Staff
Staff

l may have misunderstood, can you please send some screenshots of Service Provider  and SAML config. on Azure side.

In the same time please try to authenticate with your user  and upload the results here.

 

diagnose debug application httpsd -1
diagnose debug application samld -1
diagnose debug console timestamp enable 
diagnose debug enable
hbac
Staff
Staff

Hi @Matager,

 

What is the URL when getting "Reply URL mismatch"? Please provide screenshots of the configuration from both sides if possible. 

 

Regards, 

Labels
Top Kudoed Authors