Hi,
I am trying to integrate azure entra id into fortigate, the objective is to login into the fortigate using azure admin account.
All worked well but facing one problem. When i click SSO login the page redirects me to the microsoft login and when i enter my credentials it gives error "Reply URL mismatch", however i have verified that all URLs from Fortigate SP as same in the Azure SAML settings.
Guide i followed:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configuring-SAML-SSO-login-for-FortiGate/t...
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
config system saml
user saml is for sslvpn
... and set your digest-method to sha256 for good measure :)
Hi @Matager
Can you please send some screenshot of configuration on FGT CLI and configuration on Azure side.
config user saml
show
Created on 01-04-2024 02:23 AM Edited on 01-04-2024 02:23 AM
Please note that we are not trying to use azure for SSL-VPn, we are trying to login into the firewall using azure admin account.
Below is the output.
AFW1-FG-80F # config user saml
AFW1-FG-80F (saml) # show
config user saml
end
AFW1-FG-80F (saml) #
l may have misunderstood, can you please send some screenshots of Service Provider and SAML config. on Azure side.
In the same time please try to authenticate with your user and upload the results here.
Hi @Matager,
What is the URL when getting "Reply URL mismatch"? Please provide screenshots of the configuration from both sides if possible.
Regards,
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.