Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ThibElie
New Contributor

IPsec Dialup / SAML with multiple IdPs

Hello Team,

 

Our customers use SSL-VPN on their FortiGate with 2 IdPs:

  • one for their users (EntraID)
  • one for our users (also on EntraID - different tenant)

As migration from SSL-VPN to IPSec Dialup, we will need to use those 2 IdP with IPsec.

 

At the moment, it does not seem to be supported in IPsec Dialup (since the ike-saml-server is directly defined on the interface).

 

We did a PoC with FortiAuthenticator Cloud acting as SAML Proxy (routing based on domain), it works but it is a very expensive solution just to compensate a lack of support on the FortiGate...

 

Are there any other workaround?
Is the support of multiple IdPs planned in future FortiOS releases?

 

2 REPLIES 2
Harper_King
New Contributor

Currently, IPsec Dialup only supports a single SAML IdP per interface, so multiple IdPs aren’t natively supported. Using FortiAuthenticator as a SAML proxy is the usual workaround, though costly. Another option is to segregate users by interface or VPN profile if feasible. You may want to raise this with Fortinet support or check release notes—there’s no public confirmation yet on multi-IdP support in future FortiOS releases.

AEK
SuperUser
SuperUser

I suppose one possible solution would be to use two WAN interfaces.

AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors