Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Matt_T
New Contributor

Using FMG to configure SAML on FGT

Hello,

 

I am trying to use our FortiManager to configure SAML (using Azure) for VPN access to our remote FGT's as a "break glass" means of getting access to our FGT should the FMG be offline or the HQ site is destroyed.  The idea is that we can VPN in to the remote FGT and then access the Admin console from the inside rather than have the Admin console facing the outside.

 

I have entered all the Azure url's and certificate per what instructions I have found.  When I go to the VPN Settings and attempt to add the Azure user group I get this error.

 

user/saml/azure/ : datasrc invalid. object: vpn ssl settings authentication-rule.1:groups. detail: <group name>. solution: datasrc invalid

 

I have poured over the user group and I can find nothing that points me to what this error is referring to or how to resolve it.  I understand that the "datasrc is invalid" but I have not found the datasrc that is causing the issue.  I've tried following this link...

 

https://docs.fortinet.com/document/fortigate-public-cloud/7.2.0/azure-administration-guide/584456/co...

 

but I get stopped at the SSL VPN settings.

 

Any bread crumbs would be greatly appreciated.

 

Thanks,

 

Mattt

 

FMG: v7.4.2

FGT: v7.0.9  

1 Solution
4 REPLIES 4
Anthony_E
Community Manager
Community Manager

Hello Matt,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Anthony-Fortinet Community Team.
srajeswaran
Staff
Staff

I can see previous reports of similar issues and they were mostly due to typos/syntax issues. Do you have an active support contract? if so, please open a ticket to get the config validated by our TAC engineers.

Regards,
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.
vraev
Staff
Staff
Matt_T
New Contributor

I'm still not there yet.  but this solution has gotten me closer.  All of the configuration seems to be required via the CLI rather than the GUI.  Now I just have to sort out the VPN server being unreachable.

 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors