Hi all,
I've been working with support on this without any success so far (and they've confirmed all the setup is correct) but I'm trying to move from SSL VPN to IPSEC and have setup SAML with EntraID and this works fine when using the Apple App on iPads but I cannot get it going on a Windows machine. When I try to connect it prompts me to log into Azure and then says "you have successfully logged in" but that window just stays there and the FortiClient just shows as "Disconnect" but it's not actually connected whereas on the iPads it does the Azure bit and then that window disappears and the VPN starts to connect.
I've tried it with Windows 10 and 11 and also server 2016 and also with various versions of FortiClient and although I can see the SAML connecting in the logs on the FortiGate there is nothing after that i.e. it doesn't then start to connect the VPN, it's as though whatever should happen after that just doesn't happen.
I've got a feeling this is more of a Microsoft thing rather than a Fortinet thing so can I simply ask if anyone has got a Windows users connecting to a FortiGate using Entra SSO and IPSEC and if so then what version/release of Windows and FortiClient are you using so I can mirror it (we're not using EMS by the way just the free VPN) and also am I correct in thinking that when the SSO completes then should the "You have successfully logged on" window disappear and the VPN start to connect or is the process slightly different as it might help to know what I "should" be expecting ?
Any helps would be great.
Hello @ForgetItNet
Are you trying Ipsec + SAML + External browser if yes then may I know what is the FCT and FGT version ?
Regards
I've tried it on both external and internal browser (and Edge, Chrome and Firefox). The FGT is on 7.4.8 and I've tried various different FortiClient but currently running 7.4
Hello @ForgetItNet
Ipsec + ext browser for SAML is only working in FGT 7.6.3+ so do your testing with internal browser only and Incase if you are using Ipsec over TCP then switch it with UDP because it will be stable in fct 7.4.4
Thanks Sharmar but i can only see up to 7.4.3 on FortiCloud to download ? Is 7.4.4 due out soon or should it already be available ?
Created on 07-29-2025 09:54 AM Edited on 07-29-2025 09:54 AM
Hello @ForgetItNet
7.4.4 is expected to be release by mid of next month so currently testing with 7.4.3 (Ipsec SAML + Embedded/internal browser) with UDP only a feasible solution.
Thanks
Thanks, I'll hang on until then as I've exhausted all possible testing I think....one thing I'm not sure "might" be affecting it though (if you can confirm) as I've not found any documentation as to anyone filling this in but on the Azure side FortiClient application in the Basic SAML Configuration there is a "Relay State" (Optional) that is left empty and we have iPads that work fine so this hasn't affected them but the Windows machines seem to complete the SSO bit but then not pass/signal the actual FortiClient program to start the VPN process and in the "Relay State" bit the description shows as:
"The Relay State instructs the application where to redirect users after authentication is completed, and the value is typically a URL or URL path that takes users to a specific location within the application."
and this seems to be what I need i.e. I want the SSO once completed to redirect back to the FortiClient program to start......does this need filling in for this scenario possibly ?
Thanks
User | Count |
---|---|
2597 | |
1382 | |
801 | |
663 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.