- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SAML fortigate for IPsec dialup remote users
Dear Team,
Please assist me to create Dialup IPsec with integration SAML, i have seen already prior posts but did not work for me.
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Have you tried the configuration suggested in https://docs.fortinet.com/document/fortigate/7.2.0/new-features/951346/saml-based-authentication-for...
Are you facing any specific issues/errors after configuration?
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Error: AADSTS700016
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Can you share some more details? Where do you see this error? When do you see this error.
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Dear Suraj,
Let me try again and will revert ASAP.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Facing this issue.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is that URL the IPSec VPN gateway, or the SAML IdP?
If the IPSec VPN gateway, please ensure that it is reachable from where your FortiClient is, that IKE traffic is allowed, etc.
If that URL is the SAML IdP, please ensure that it is reachable from where your FortiClient is WITHOUT a tunnel. SAML authentication essentially functions like this:
- FortiClient connects to FortiGate (or other IPSec VPN gateway) to establish tunnel
- FortiGate says: "No, go to this <URL/IP of SAML IdP> and authenticate, then come back"
- FortiClient then tries to connect to URL/IP as specified by FortiGate directly, without a tunnel, and authenticate there
Depending on whether FortiClient fails to connect to the IPSec VPN gateway, or the SAML IdP, further troubleshooting on the connection between them is required to determine what is going on.
Cheers,
Debbie
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Well, URL is VPN gateway, authentication is successful doing, after authentication its sucked.
