Description This article describes how to make a CMP password based
initialization request from FortiGate to FortiAuthenticator. Scope
Fortigate7.6.X FortiAuthenticator 6.0.X. Solution Follow admin guide
instructions to enable the service on the Fort...
Description This article describes how to configure and use a custom
SAML user attribute. Scope Fortiauthenticator 6.5, 6.6. Solution If an
SAML app or SP expects a certain user attribute different from the
existing pre-configured ones (DN, sAMAccoun...
Description This article describes how to configure Nextcloud and
FortiAuthenticator for OpenID Connect (OIDC) authentication Scope
FortiTrust Identity and FortiAuthenticator v6.5, v6.6. Solution This has
been tested with the following versions: Fort...
Description This article describes a potential fix for
FortiAuthenticator SAML IDP error 403. The same event produces the
following error: 'Access Denied, access to this resource via HTTP is not
allowed with the current network interface configuratio...
Description This article explains how it is best to configure Username
format in Radius and other authentication policies when UPN
(userPrincipalName) is used. Scope The following settings instruct the
FortiAuthenticator on how to read the credential...
hi there, Most likely if you specify only the logon events (instead of
0, 1, 2) you won't have the users logged off anymore.Check what are the
correct IDs for your server OS. 6) Logon Event ID poller. Increase the
level to '2' instead of '0' of visib...
Hi there, I hope I got this right.If the same public IP/FQDN has been
moved from FGT to LB, you still have the same public IP/FQDN in "config
user saml", and LB is correctly configured to fw the saml auth request
to the FGT, then this is expected to ...
Hi there, * close*timeout*client-rst* accept These actions are also part
of normal operation, they don't necessarily indicate an issue.Need to
correlate some more outputs in order to determine if these events are an
issue. Please follow these trouble...
Hi there, Can you link this issue to any change in your environment?Have
you tested other devices/FortiClient versions?Is it possible for an
effected user to use for a while web ssl portal instead of FCT tunnel
mode?That should help to identify if th...
Hi there, It's unclear to me what do you mean by "Does Foticlient
support to dialup IPsec VPN or we have to configure separate Forticlient
configuration at Fortigate Firewall." If ipsec dialup with 2fa is what
you're after, please check the docs bell...