Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
echo
Contributor II

VPN+SSO possible?

Hello! I am searching for possibilities to configure client VPN with SSO. So far I don' t understand if this is possible at all, can' t find any example from Fortinet docs. I tried to start doing client VPN and use Radius SSO group, but just got stuck somewhere: the SSO user group that I defined couldn' t be selected for phase1-interface. In addition to that, I found fortios-handbook-50.pdf from http://docs.fortinet.com/d/fortigate-fortios-handbook which has such information: --- Page 482: The Fortinet Single Sign On (FSSO) agent enables FortiGate units to authenticate these network users for security policy or VPN access without asking them again for their username and password. /---/ The FSSO user groups that you created are used in security policies and VPN configurations to provide access to different services and resources. Page 508: FSSO user groups cannot have SSL VPN or dialup IPsec VPN access. --- Does that mean that SSO can' t be used for VPN or what? Cookbook 507 also didn' t have any such recipe. I have set up IPSEC and SSL VPNs for clients (for FortiClient and Shrew) with AD authentication (LDAP and Radius) and local authentication several times so I have that knowledge to go on with, but I have no experience with SSO, hence my noob question :)
6 REPLIES 6
Dipen
New Contributor III

If you want to use AD Authentication with SSL-VPN then LDAP authentication will works for you. FSSO I have not heard to work with SSL-VPN. Please note that SSL-VPN is for remote users who of course will not be communicating with AD Server.

Ahead of the Threat. FCNSA v5 / FCNSP v5

Fortigate 1000C / 1000D / 1500D

 

Ahead of the Threat. FCNSA v5 / FCNSP v5 Fortigate 1000C / 1000D / 1500D
PMD
New Contributor

FSSO doesnt work with SSL VPN as Dipen informed you can intergrate authentication with LDAP.
rwpatterson
Valued Contributor III

Think about it the logical way. For SSO to work, a user needs to be authenticated first, then their login credentials are passed from one system to the next. Outside users are not authenticated before they attempt to log into the firewall. You can user the same login database (AD) for authentication for both incoming (via LDAP) and outgoing (via FSAE/FSSO). Configuration for each is vastly different, but as far as I am aware, there is no Single Sign On for incoming connections.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
echo
Contributor II

OK, thank you all, I see that these two things seem to have different purposes.
albertommo
New Contributor

Maybe I'm too late, but I've heard about VPN SSL SSO using SAML so, you can configure it to use it with Azure SSO or FortiAuthenticator as IdP. Check this link https://community.fortinet.com/t5/FortiGate/Technical-Tip-Create-SSL-VPN-with-Azure-SAML-SSO-Authent...

!
!
aahmadzada
Staff
Staff

Following up, it is possible.
Here is the KB article for that:

https://community.fortinet.com/t5/FortiGate/Technical-TIp-Configure-Fortinet-Single-Sign-On-FSSO-for...

 

 

Ahmad
Labels
Top Kudoed Authors