Fortinet black logo

Cookbook

Importing the IdP certificate and metadata on the FortiAuthenticator

Copy Link
Copy Doc ID 53d09085-7746-11e9-81a4-00505692583a:733895
Download PDF

Importing the IdP certificate and metadata on the FortiAuthenticator

  1. To import the Google IdP data, on the FortiAuthenticator, go to Fortinet SSO Methods > SSO > SAML Authentication and import the IdP metadata and certificate downloaded during the Google IdP Information step earlier.
  2. This automatically fills the IdP fields. Make sure to select OK to save these changes.

  3. Create a new FortiGate filter for FSSO Push. Go to Fortinet SSO Methods > SSO > FortiGate Filtering and select Create New.
  4. Enter a name and the FortiGate’s wan-interface IP address. Select OK and then enable Fortinet Single Sign-On (FSSO).

    Select Create New to create an SSO group filtering object. The group filtering object name must once again match the original SAML group user name (saml_users).

    Select OK to apply all changes.

Importing the IdP certificate and metadata on the FortiAuthenticator

  1. To import the Google IdP data, on the FortiAuthenticator, go to Fortinet SSO Methods > SSO > SAML Authentication and import the IdP metadata and certificate downloaded during the Google IdP Information step earlier.
  2. This automatically fills the IdP fields. Make sure to select OK to save these changes.

  3. Create a new FortiGate filter for FSSO Push. Go to Fortinet SSO Methods > SSO > FortiGate Filtering and select Create New.
  4. Enter a name and the FortiGate’s wan-interface IP address. Select OK and then enable Fortinet Single Sign-On (FSSO).

    Select Create New to create an SSO group filtering object. The group filtering object name must once again match the original SAML group user name (saml_users).

    Select OK to apply all changes.