Configuring the Security Fabric with SAML:Here we assume you have already set the appropriate Fabric Connector configurations. This guide will only explain how to configure the SP and IDP settings.
| Section |
|---|
|
| Column |
|---|
Log in to the root FortiGate. Go to Security Fabric > Fabric Connectors and double-click the Security Fabric Setup card.
|
| Column |
|---|
|
| Panel |
|---|
| borderColor | #9EBEE5 |
|---|
| bgColor | #f0f0f0 |
|---|
| borderWidth | 1px |
|---|
| 
|
|
|
...
| Section |
|---|
|
| Column |
|---|
In the Topology tree, hover over a FortiGate and click Configure.Fabric Connector Edit screen go down to where it says SAL Single Sign-On and click Advance Options
|
| Column |
|---|
|
| Panel |
|---|
| borderColor | #9EBEE5 |
|---|
| bgColor | #f0f0f0 |
|---|
| borderWidth | 1px |
|---|
| Image Removed Image Added
|
|
|
| Section |
|---|
|
| Column |
|---|
In the SAML SSO Window Specify the SP address. This is essentially the URL or the IP address of the Fortinet UI you wish to log onto.
Expand SP details |
| Column |
|---|
|
| Panel |
|---|
| borderColor | #9EBEE5 |
|---|
| bgColor | #f0f0f0 |
|---|
| borderWidth | 1px |
|---|
| Image Added
|
|
|
Log back in. to the DualShield Admin Console
| Section |
|---|
|
| Column |
|---|
Go to SSO>Service ProvidersClick Ok in the configure window |
| Column |
|---|
|
| Panel |
|---|
| borderColor | #9EBEE5 |
|---|
| bgColor | #f0f0f0 |
|---|
| borderWidth | 1px |
|---|
| Image Removed Image Added
|
|
|
Click on
Image Added on the top right.
| Section |
|---|
|
| Column |
|---|
Once installed the Certificate needs to be exported Export it as a Base-64 encoded X.509 (.CER)Fill in the details as per screenshot on right and make sure you select SAML 2.0(Without Metadata) as Type. |
| Column |
|---|
|
| Panel |
|---|
| borderColor | #9EBEE5 |
|---|
| bgColor | #f0f0f0 |
|---|
| borderWidth | 1px |
|---|
| Image Removed Image Removed
|
|
|
...
| Image Added
|
|
|
| Section |
|---|
|
| Column |
|---|
Copy and Paste the Entity ID, ACS and Logout URL from the SP details on the Fortinet UI (see above)
|
| Column |
|---|
|
| Panel |
|---|
| borderColor | #9EBEE5 |
|---|
| bgColor | #f0f0f0 |
|---|
| borderWidth | 1px |
|---|
| Image Added
|
|
|
| Section |
|---|
|
| Column |
|---|
Upload the exported CER file.The completed Service Provider dialogue box will look like this: |
| Column |
|---|
|
| Panel |
|---|
| borderColor | #9EBEE5 |
|---|
| bgColor | #f0f0f0 |
|---|
| borderWidth | 1px |
|---|
| Image Removed | Image Added
|
|
|
Click Save.