Hi, I'm trying to move from SSL-VPN to IPSec, and no matter what I do, my forticlient is getting timeout on connect when I'm trying to use SAML.
My SAML port is 1443
SAML is working perfectly fine with SSL-VPN.
I'm on version v7.6.3.
I made to read and follow all the guidelines I could have found on the forums and in forti website.
If I try to connect with out SAML, it works fine.
I'm pretty lost at the moment because FortiClient doesn't seem to generate any logs for this connection attempt as well.
hi,
can you share the output for
show system global | grep ike-saml
show system interface WAN-Intf
show ipsec vpn phase1-interface | grep eap
show ipsec vpn phase1-interface | grep authusrgrp
a similar config guide can be found and followed from here, https://www.andrewtravis.com/blog/ipsec-vpn-with-saml
and you can start a debug on the FGT for saml in order to see where the issue might be and if it's related to saml or even a ipsec.
diag debug application samld -1
diag debug enable
diag debug application ike -1 ( you can narrow it down and do a filter before this with diagnose vpn ike filter <> and choose a param to look for, like rem-addr4 for a specific ip address initiating )
There is no FortiGate 91F. Maybe you have a 91G, which doesn't have SSL-VPN anyway nowadays depending on the version, and will lose with every version soon, so you only have IPsec.
Same here.. FortiClient 7.4.3 and FortiOS 7.6.3 ... just a timeout after successful saml auth...
Please check with the Samld and VPN logs for the logout reason.
No logs - saml auth working. Than nothing.. seems to work when using FortiAuthenticator.. not working when connecting directly from FGT to Entra
User | Count |
---|---|
2587 | |
1378 | |
796 | |
658 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.