Hello Team,
Our customers use SSL-VPN on their FortiGate with 2 IdPs:
As migration from SSL-VPN to IPSec Dialup, we will need to use those 2 IdP with IPsec.
At the moment, it does not seem to be supported in IPsec Dialup (since the ike-saml-server is directly defined on the interface).
We did a PoC with FortiAuthenticator Cloud acting as SAML Proxy (routing based on domain), it works but it is a very expensive solution just to compensate a lack of support on the FortiGate...
Are there any other workaround?
Is the support of multiple IdPs planned in future FortiOS releases?
Currently, IPsec Dialup only supports a single SAML IdP per interface, so multiple IdPs aren’t natively supported. Using FortiAuthenticator as a SAML proxy is the usual workaround, though costly. Another option is to segregate users by interface or VPN profile if feasible. You may want to raise this with Fortinet support or check release notes—there’s no public confirmation yet on multi-IdP support in future FortiOS releases.
I suppose one possible solution would be to use two WAN interfaces.
| User | Count |
|---|---|
| 2792 | |
| 1424 | |
| 812 | |
| 748 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.