Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Ryan_INN
New Contributor

IPsec + Entra SAML - multiple IPsec tunnel

I am looking for assistance getting a multiple IPsec tunnel configuration working on a single WAN IP.

 

Utilizing IKEv2 for Entra SAML authentication.  I have two IPsec configurations, each are configured the same with the exception of PSK and Local ID. Forgot one other note: The second tunnel is configured to use IPv4 Split-Tunnel. 

I can successfully connect to the "primary" one or the employee one I setup first. As long as my PSK/Local ID and DHG/Encryption in my forticlient is set correctly it authenticates and connects. If I attempt to switch to the Vendor intended tunnel and use that configuration, I get through Entra Authentication and it hangs and fails to connect. 

 

Details

120G running v7.4.8

Using Forticlient free v7.4.3.1790

 

Hoping someone can point me in the right direction of what I am missing. I was really expecting the Local ID to make this simple to configure. 

I have tried changing Encryption & DH groups on the second tunnel phase1/2 (on top of different PSK/local ID) but that has not resolved the problem either. 

 

Thank you

1 REPLY 1
Ryan_INN
New Contributor

Think after some more digging I figured out my own issue. 

 

set eap enable
set eap-identity send-request

 

CLI only and don't get set when setting IKEv2 in GUI. Forgot about that when I created the first tunnel. 

My authentication is accepted, connection made and FW policy based on Group seems to be working as expected to limit access to internal resources. 

 

Hopefully this can help someone else if they run into a similar issue. 

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors