Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
jentino
New Contributor

Forticlient on mobile redirects to error page during SSL-VPN/SAML Authentication

Hello everyone,

 

I am using Fortigate 7.0.12 setting up SSL-VPN with Azure MFA using FortiClient mobile (7.2.0.0101) .

 

The setup works fine but gives a bad user experience for thousands of users on mobile (iOS and Android)  by throwing an error webpage which is trying to reach 127.0.0.1:8020 (Error: This site can't be reached 127.0.0.1 refused to connect). I do not expect the FortiClient to be running anything on port 8020, or should it?

 

This error webpage is shown during the SAML authentication flow, and once it is promptly closed the connection is authenticated and browsing is normal. Has anyone found a workaround for this or some pointers to avoid this redirect error webpage?

 

Some info I found online about this redirect:

 

#https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/364443/using-a-browser-as-a...

 

I was hoping I could change the 127.0.0.1 to something meaningful like a banner webpage instead. I can change the port using cli from 8020 to any port but not the hostname.

 

P.S: This 127.0.0.1:8020 error webpage does not occur when using the laptop/desktop FortiClient.

 

 

1 Solution
srajeswaran
Staff
Staff

Can you test the behavior in FortiClient version 7.0.7 or 7.0.9 ? Also, whats the behavior when you change the redirect port to 0 ?

config vpn ssl settings
set saml-redirect-port 0
end

 

Regards,
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.

View solution in original post

8 REPLIES 8
srajeswaran
Staff
Staff

Can you test the behavior in FortiClient version 7.0.7 or 7.0.9 ? Also, whats the behavior when you change the redirect port to 0 ?

config vpn ssl settings
set saml-redirect-port 0
end

 

Regards,
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.
jentino

Hi Suraj,

 

That was pretty quick! Now client embeds the page within itself instead of creating an external pop up and the error is gone. Thanks a lot for your prompt reply.

 

P.S: The client is download directly from the google play store.

Guimass

I tried this myself because I have the same issue. It started working on Android phones but then the desktop Forticlient would stop working. FortiClient displays a message showing that the SAML redirect port is unavailable. How did you get around that?

Thanks

azv
New Contributor

The same problem. If I make changes :

config vpn ssl settings
set saml-redirect-port 0
end

Then VPN from PC do not work.

"SAML redirect port is unavailable"

ICTSZU
New Contributor II

Hi,

 

this solution works only for mobile devices.

If we change the port, all desktop client stop working.

So this is not really a solution.

 

Can you please reopen this topic internally and fix this bug?

 

Thanks

LMS
New Contributor

Ran across the same issue after upgrading our Fortigate 1100's to 7.0.14, have a mix of computers and mobile devices in our environment, so naturally this "fix" does not help us either..

 

Please reopen this topic, thanks! :) 

LMS
New Contributor

Update: Found similar case where upgrade to 7.0.14 breaks Android VPN with SAML. Fortinet says this is known and will be released a new firmware for FC on android (7.2.2) soon. 
https://community.fortinet.com/t5/Support-Forum/VPN-not-working-on-mobile-devices-after-7-0-14-upgra...

Juan_Carlos_Cuesta

We have FortiClient VPN 7.2.4.0972 on Windows and 7.2.2.0127 on Android.

 

After applying the configuration proposed by srajeswaran, we also disabled the option to use external navigator on FortiClient Windows and it started working again.

 

Hope this helps.

 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors