Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Andrzej_PL
New Contributor III

IPSEC VPN Dial Up with SAML and FIDO2 support

Hi, I'm trying to configure an IPSEC VPN dial-up with saml and fido2 (yubikey) using the External Browser as User-agent for SAML Login option - it's not working. It works for SSLVPN, but not for IPSEC. The client version is 7.2.12. Could it be that it's not working? It works without problems using credentials via Microsoft Authenticator with the External Browser as User-agent for SAML Login option disabled, but when I enable it and use the FIDO2 key method, the browser displays a message that I've logged in, but the tunnel doesn't establish. The tunnel is configured based on ike2 with the networkid parameter. Has anyone else encountered this problem?

Regards

 

1 Solution
ezhupa
Staff
Staff

Hello,
According to official DOC:
https://docs.fortinet.com/document/fortigate/7.6.4/administration-guide/951346/saml-based-authentica...
"
Dialup IPsec VPN with SAML using an external browser for authentication is supported starting from FortiOS 7.6.1, FortiClient (Windows) and (macOS) 7.2.5 and 7.4.1 and FortiClient (Linux) 7.4.3.
"

Hope this helps!

View solution in original post

2 REPLIES 2
ezhupa
Staff
Staff

Hello,
According to official DOC:
https://docs.fortinet.com/document/fortigate/7.6.4/administration-guide/951346/saml-based-authentica...
"
Dialup IPsec VPN with SAML using an external browser for authentication is supported starting from FortiOS 7.6.1, FortiClient (Windows) and (macOS) 7.2.5 and 7.4.1 and FortiClient (Linux) 7.4.3.
"

Hope this helps!

Andrzej_PL
New Contributor III

Thanks for the info - today I will upgrade to the mature 7.6.5 version

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors