Hi all,
We have just got our iPads to connect using the FortiClient app with IPSEC and SSO and this works fine so the user can log in using their Azure details and then the login window shows that they have successfully logged in and this window then disappears and the VPN then connects however we've noticed that the Windows FortiClient app doesn't have the SSO option with IPsec (correct me if I'm wrong on that but it only seems to be for SSL) so we're trialling the ZTNA with a view to getting EMS (we don't have EMS installed yet though) and found this DOES have the SSO option with IPsec so I've configured it the same as the iPads and it shows we're successfully logged into the SSO but then whereas on the iPads the window disappears, this doesn't happen...the window just stays there and if we close it then the VPN goes from disconnect to connect as though it's just disconnected but if I check the VPN status without closing the window then it's not connected anyway ?
I've tried both the internal and external browser and there are no connection logs at all on the FortiAnalyzer to show it's even TRYING to connect. The ZTNA program logs also show nothing apart from "Checking for updates"
I've read a few posts on this but they all say to update the client however this is the latest version off the Fortinet website (7.4.3.1790).
I'm "assuming" this SHOULD work without the EMS shouldn't it ? Any advice on this would be great.
Thanks
Hello,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Hello,
If ZTNA SSO shows as logged in but the VPN does not connect, follow these troubleshooting steps:
If the issue persists after these steps, further investigation into the specific configuration and network environment may be necessary.
Thanks, I've checked all that as much as I can and it does all look ok but do I need EMS for this to work on the windows machines as it's not been needed for the iPads to work ?
I've been advised by a supplier that we don't need EMS or ZTNA for Windows to connect using SSO so I've gone back to the free FortiClient VPN only program but I'm still getting the same issue in that the SSO window (either the FortiClient internal or Windows external browser) shows successfully logged in but then nothing happens...the VPN only shows "disconnect" even though it's not actually connected (and doesn't even try). If I don't use SSO then it works fine so I know the VPN settings are correct. Looking at a lot of forums there is talk of having to get a "custom installer" with a fix to it but this was in version 7.2 and I've got the latest 7.4 so I'm stuck on what to check next as the logs don't show anything either ?
Just in addition that i've been reading some other posts that have got it working and have ran a fnbamd debug and got this below but nothing else after it....looking at the other post here for example there should be a lot more ( Solved: Forticlient IPSEC w/ SAML stuck in connecting - Page 2 - Fortinet Community )
FG # diagnose debug disable
FG # diagnose debug reset
FG # diagnose debug console timestamp enable
FG # diagnose debug enable
FG # diagnose debug application fnbamd 255
Debug messages will be on for 30 minutes.
FG # 2025-06-03 15:15:20 [2458] handle_req-Rcvd auth cache message
2025-06-03 15:15:20 [139] __saml_auth_cache_push-Hash bucket 163
2025-06-03 15:15:20 [145] __saml_auth_cache_push-Update 'B63B090E52CC4000B9266A724A85B24B', SAML_server='Azure', vfid=0
2025-06-03 15:17:20 [57] __auth_cache_maintainer-Continue the maintainer of Azure. Current entries: 1
I have also disabled EAP authentication on the VPN to see if this resolves it without success (so i think it should just do the SSO and if that works then the VPN should connect)
Having not got this working on a Windows machine it looks like it's this that "should" be occurring:
User | Count |
---|---|
2571 | |
1365 | |
796 | |
653 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.