FortiAuthenticator
FortiAuthenticator provides access management and single sign on.
kiri
Staff
Staff
Article Id 307297
Description

This article describes a potential fix for FortiAuthenticator SAML IDP error 403.

The same event produces the following error: 'Access Denied, access to this resource via HTTP is not allowed with the current network interface configuration. Please check your network interface configuration'.

Scope FortiAuthenticator v.6.6.0, v6.5.4.
Solution

Make sure that:

  1. The required services (HTTP, HTTPS, SAML IdP) are enabled on the service interface.
  2. The SAML SP is using the FortiAuthenticator FQDN configured in Authentication, SAML IDP, General, IdP-initiated login URL.

 

1.png

 

  1. The server address is the same as Device FQDN.

 

2.png

 

  1. If the server address is not the same as the Device FQDN and it cannot be changed, add the server address to the GUI under Admin -> System access: 'Additional allowed hosts/domain names'.

 

3.png

 

4.png