ince FortiOS going to obsolete SSLVPN from 7.6 onward,
Information
Local User Database
LDAP information
Radius
SAML information
Related document for SAML
Technical Tip: Configuring IPsec VPN client-to-site with Azure SAML authentication
BYOD
Bye, if a domain environment, netlogon details doesn't send to AD so FSSO wont work.
Other site information
Forti VM with FortiOS 7.4.8
diagnose debug application authd -1 when turn on this debug the SAML wont work till disable debug
Update 17 July 2025,
FSSO
Due to AD behavior, FSSO also has some limitation on user identification, example IPSEC success with limvuihan (IP 192.168.10.1) but I remote desktop with domain admin pbbadmin to another server due to AD behavior, the logon event id will be update that pbbadmin IP address same as your IPSEC IP which is 192.168.10.1. So all the defined rules based on grouping wont work and unable access. Alternative is to ignore the pbbadmin user list at collector agent.
If your RDP username is same as your FortiClient Login ID mostly will be disconnect.
Update 1st August 2025
So when there is user connect the FortiClient IPsec, cant change the Split Tunnel Parameter , is not flexible as SSL VPN Tunnel request user to reconnect the VPN to get the new route.
You can use network id or localID identifier to simulate groups with IPSEC
I'm sure FTNT will have an enhancement soon
Yes for small scale client, but no for large scale enterprise.
7.4 end of engineering at May 2026, not much time left for 7.6 improvement.
Since IPsec over TCP w/ Free FortiClient VPN wouldn't be supported any more. FGT is no longer an option for many of smaller, non-corporate, users like my home. UDP IPsec is widely blocked over public WiFi, hotel WiFi, and often overseas access. At least an EMS server/EMS Cloud license is required to do either IPsec over TCP or ZTNA for remote access.
I'm now looking for something else like OPNsense to replace my home 40F before upgrading it from 7.4.8 to 7.6.4 or later version.
Toshi
User | Count |
---|---|
2551 | |
1356 | |
795 | |
646 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.