Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
assim
New Contributor

IPsec Azure SAML just getting timeout

Hi, I'm trying to move from SSL-VPN to IPSec, and no matter what I do, my forticlient is getting timeout on connect when I'm trying to use SAML.

My SAML port is 1443

SAML is working perfectly fine with SSL-VPN.

I'm on version v7.6.3.
I made to read and follow all the guidelines I could have found on the forums and in forti website.
If I try to connect with out SAML, it works fine.

I'm pretty lost at the moment because FortiClient doesn't seem to generate any logs for this connection attempt as well.

10.0.0.0.1 192.168.1.254
5 REPLIES 5
funkylicious
SuperUser
SuperUser

hi,

can you share the output for

show system global | grep ike-saml

show system interface WAN-Intf

show ipsec vpn phase1-interface | grep eap

show ipsec vpn phase1-interface | grep authusrgrp 

 

a similar config guide can be found and followed from here, https://www.andrewtravis.com/blog/ipsec-vpn-with-saml 

and you can start a debug on the FGT for saml in order to see where the issue might be and if it's related to saml or even a ipsec.

diag debug application samld -1

diag debug enable

diag debug application ike -1 ( you can narrow it down and do a filter before this with diagnose vpn ike filter <> and choose a param to look for, like rem-addr4 for a specific ip address initiating )

"jack of all trades, master of none"
"jack of all trades, master of none"
nokilmo2
New Contributor

There is no FortiGate 91F. Maybe you have a 91G, which doesn't have SSL-VPN anyway nowadays depending on the version, and will lose with every version soon, so you only have IPsec.

https://9apps.ooo/
michael2406
New Contributor III

Same here.. FortiClient 7.4.3 and FortiOS 7.6.3 ... just a timeout after successful saml auth...

VinayHM
Staff
Staff

Please check with the Samld and VPN logs for the logout reason.

Vinay HM
michael2406
New Contributor III

No logs - saml auth working. Than nothing.. seems to work when using FortiAuthenticator.. not working when connecting directly from FGT to Entra

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors