Hi, I'm trying to configure an IPSEC VPN dial-up with saml and fido2 (yubikey) using the External Browser as User-agent for SAML Login option - it's not working. It works for SSLVPN, but not for IPSEC. The client version is 7.2.12. Could it be that it's not working? It works without problems using credentials via Microsoft Authenticator with the External Browser as User-agent for SAML Login option disabled, but when I enable it and use the FIDO2 key method, the browser displays a message that I've logged in, but the tunnel doesn't establish. The tunnel is configured based on ike2 with the networkid parameter. Has anyone else encountered this problem?
Regards
Solved! Go to Solution.
Hello,
According to official DOC:
https://docs.fortinet.com/document/fortigate/7.6.4/administration-guide/951346/saml-based-authentica...
"
Dialup IPsec VPN with SAML using an external browser for authentication is supported starting from FortiOS 7.6.1, FortiClient (Windows) and (macOS) 7.2.5 and 7.4.1 and FortiClient (Linux) 7.4.3.
"
Hope this helps!
Hello,
According to official DOC:
https://docs.fortinet.com/document/fortigate/7.6.4/administration-guide/951346/saml-based-authentica...
"
Dialup IPsec VPN with SAML using an external browser for authentication is supported starting from FortiOS 7.6.1, FortiClient (Windows) and (macOS) 7.2.5 and 7.4.1 and FortiClient (Linux) 7.4.3.
"
Hope this helps!
Thanks for the info - today I will upgrade to the mature 7.6.5 version
| User | Count |
|---|---|
| 2862 | |
| 1445 | |
| 829 | |
| 820 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.