Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Janfi
New Contributor II

VPN - 2 SAML

Hello,

 

I want to ask you for advice. I am currently managing a FortiGate device where I am running a VPN setup. Within this VPN, I have a requirement to authenticate users against two separate Azure tenants. Both tenants are configured with FortiGate SSL VPN applications.

 

I have tested the connection, and I observed that when users are in different tenants, the authentication always attempts to validate against a single SAML provider (Users can be authenticated through one tenant, but users from the second tenant are experiencing issues. The system attempts to authenticate them through the first tenant, where they do not have access). I am looking for a solution that allows the system to attempt authentication in the second tenant if the initial SAML authentication fails.

 

I would appreciate any advice.

Jan

 

1 Solution
ndumaj

Sure, using realms you can differentiate users to connect in two different IDPs.

BR

- Happy to help, hit like and accept the solution -

View solution in original post

12 REPLIES 12
rinshadabbkr

HI,

Could you please help me configure Realms? I'm also facing this same tenant issue and stuck at realms.

Janfi
New Contributor II

Hello,

 

For SAML MFA configuration, I recommend this excellent tutorial: Link . After completing it, you can use realms, which need to be added under VPN > SSL-VPN Realms and VPN > SSL-VPN Settings. There, you'll find the Authentication/Portal Mapping section, where you need to assign a group for VPN access and set the corresponding realm.

Once this configuration is complete, your VPN will allow access via URLs such as:
https://yourDomain.../andYourRealm.

This setup allows you to support multiple tenants. For example:
https://yourDomain.../andYourRealm1
https://yourDomain.../andYourRealm2

And so on...

These addresses will then be used as gateways when connecting.

 

Best regards,

Jan

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors