Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mclut
New Contributor II

Is 3rd party SAML provider possible with ZTNA?

Quick question. 

 

Is it possible to use a SAAS SSO provider such as Okta, MS etc and using SAML? This is our current setup for VPN, but there seems to be a hitch when you need to involve Authentication rules because of the interface and protocol preference.

 

Is the LDAP portion required for this? And not just relying upon the SP user data base? 

1 Solution
mclut
New Contributor II

So the issue is a "bug" but no yet acknowledged.

 

Issues arise with modification of the SAML user and whether or not the ZTNA server is created before or after this.

 

This is not working as intended as of this time and testing on multiple versions of FCT. 7.2.0 --- 7.2.8

The work around is to re-create the SAML User and ZTNA server/s.

View solution in original post

2 REPLIES 2
rbraha
Staff
Staff

Hi @mclut 

 

Check this guide below it might help, in this case is used FAC as SAML IDP.

 

https://docs.fortinet.com/document/fortigate/7.6.2/administration-guide/259754/ztna-application-gate...

mclut
New Contributor II

So the issue is a "bug" but no yet acknowledged.

 

Issues arise with modification of the SAML user and whether or not the ZTNA server is created before or after this.

 

This is not working as intended as of this time and testing on multiple versions of FCT. 7.2.0 --- 7.2.8

The work around is to re-create the SAML User and ZTNA server/s.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors