Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
guchinife
New Contributor

Configuring AP(Wifi) access with Single Sign-ON (SSO)

Hello.
I have configured in FotiNet a VPN-SSL connection with SSO (Single Sing-On) against Azure (SAML). This configuration is working correctly for me
Now I want to configure the FortiAP to validate also the users against AZure with SSO and use captive portal.
How do I have to do this configuration? Do I have to add a new SSO in Azure and FortiNet or can I use the existing one?
Thanks

6 REPLIES 6
adimailig
Staff
Staff

You need to create a new Enterprise Application / SSO on Azure and on Fortigate.
You may refer to below guide.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Wireless-Authentication-using-SAML-Credent...

Best Regards,

Arnold Dimailig
TAC Engineer
guchinife

Hi, I have configured the Azure user authentication with the above link, but when I connect to the Wifi, a browser opens but does not redirect me to the captive portal.
It also happens to me on the guest wifi that I have configured only the captive portal. When I connect to the wifi, a browser opens but the captive portal does not appear.

guchinife

I can't get the wifi to connect to the captive portal.
Not even on the guest wifi that logs in against local Forti users.
A browser opens and tries to connect to www.msftconnecttest.com/redirect, but does not reach the captive portal.

Can you help me with this issue?

Thanks

hbac

Hi @guchinife,

 

On that article at step 5. You can add the following FQDNs to the exempt policy and test. 

 

"login.microsoft.com"

"login.windows.net"

 

Regards, 

guchinife
New Contributor

Hello
I am already redirected to the Microsoft login.
The problem now is that after logging in with my username and password it redirects me to
the internal IP of the Firewall https://192.168.1.1:1003/saml/metadata and shows the following error "was not found in the directory".

hbac

@guchinife

 

Have you tested and make sure the SAML configuration is correct and working? Please verify with https://community.fortinet.com/t5/FortiGate/Technical-Tip-Wireless-Authentication-using-SAML-Credent...

 

Regards, 

Labels
Top Kudoed Authors