Dear Team,
Please assist me to create Dialup IPsec with integration SAML, i have seen already prior posts but did not work for me.
Have you tried the configuration suggested in https://docs.fortinet.com/document/fortigate/7.2.0/new-features/951346/saml-based-authentication-for...
Are you facing any specific issues/errors after configuration?
Error: AADSTS700016
Can you share some more details? Where do you see this error? When do you see this error.
Dear Suraj,
Let me try again and will revert ASAP.
Facing this issue.
Is that URL the IPSec VPN gateway, or the SAML IdP?
If the IPSec VPN gateway, please ensure that it is reachable from where your FortiClient is, that IKE traffic is allowed, etc.
If that URL is the SAML IdP, please ensure that it is reachable from where your FortiClient is WITHOUT a tunnel. SAML authentication essentially functions like this:
- FortiClient connects to FortiGate (or other IPSec VPN gateway) to establish tunnel
- FortiGate says: "No, go to this <URL/IP of SAML IdP> and authenticate, then come back"
- FortiClient then tries to connect to URL/IP as specified by FortiGate directly, without a tunnel, and authenticate there
Depending on whether FortiClient fails to connect to the IPSec VPN gateway, or the SAML IdP, further troubleshooting on the connection between them is required to determine what is going on.
Cheers,
Debbie
Well, URL is VPN gateway, authentication is successful doing, after authentication its sucked.
User | Count |
---|---|
2094 | |
1182 | |
770 | |
451 | |
344 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.