Fortinet IPsec VPN – RSA Ready Implementation Guide
a day ago

Certified: August 13, 2026

     

Solution Summary

This guide describes Fortinet IPsec VPN integration with RSA using SAML 2.0. Use this information to determine which use case and integration type your deployment will employ.

      

Use Case

Fortinet IPsec VPN can be integrated with RSA using SAML Relying Party. When integrated, users must authenticate with RSA to sign in to Fortinet IPsec VPN. 
      

Integration Types

SSO integrations use SAML 2.0 or HFED technologies to direct users' web browsers to Cloud Access Service (CAS) for authentication. The integration provides Single Sign-On (SSO) using Relying Party. 
   

  • Relying Party integrations use SAML 2.0 to direct users’ web browsers to CAS for authentication. With Relying Party integration, CAS can manage either additional authentication only or both primary authentication (for example, user ID and password) and additional authentication, depending on the service provider's capability.
                     

Supported Features

This section shows all the supported features by integration type and by RSA components. Use this information to determine which integration type and RSA component your deployment will use. The next section in this guide contains the instruction steps for how to integrate RSA with Fortinet IPsec VPN using each integration type.

       

Fortinet IPsec VPN Integration with CAS

Authentication Methods
MFA API
RADIUS
SAMLOIDC
Relying Party
My Page
Relying PartyMy Page SSO
ApproveNot testedNot testedSupportedNot testedNot tested
Not tested
Approve with Code Matching
Not tested
Not tested
Supported
Not tested
Not tested
Not tested
LDAP PasswordNot testedNot testedSupportedNot testedNot tested
Not tested
SecurID OTPNot testedNot testedSupportedNot testedNot tested
Not tested
Authenticate OTPNot testedNot testedSupportedNot testedNot tested
Not tested
Device BiometricsNot testedNot testedSupportedNot testedNot tested
Not tested
Device Biometrics with Code Matching
Not testedNot tested
Supported
Not tested
Not tested
Not tested
SMS OTPNot testedNot testedSupportedNot testedNot tested
Not tested
Voice OTPNot testedNot testedSupportedNot testedNot tested
Not tested
FIDO Security KeyNot testedNot testedSupportedNot testedNot tested
Not tested
QR CodeNot testedNot testedSupportedNot testedNot tested
Not tested
Emergency Access CodeNot testedNot testedSupportedNot testedNot tested
Not tested

                     

Configuration Summary

This section contains instruction steps that show how to integrate Fortinet IPsec VPN with RSA using all of the integration types. 
This document is not intended to suggest optimum installations or configurations. It is assumed that the reader has both working knowledge of all products involved, and the ability to perform the tasks outlined in this section. Administrators should have access to the product documentation for all products to install the required components.
All RSA and Fortinet IPsec VPN components must be installed and working prior to the integration.
This section of the guide includes links to the appropriate sections for configuring both sides for each use case.
      

Integration Configuration

CAS

                        

    RSA Terminology Changes

    The following table describes the differences in the terminologies used in the different versions of RSA products and components. 

    Previous VersionNew VersionExamples/Comments
    Cloud Authentication ServiceCloud Access Service
    Token

    OTP CredentialSecurID OTP Credential
    AuthenticatorHardware Authenticator
    Tokencode

    OTPSecurID OTP, SMS OTP, Voice OTP
    Access CodeEmergency Access Code
    SecurID Authenticate appRSA Authenticator appRSA Authenticator app for iOS and Android, RSA Authenticator app for Windows
    DeviceAuthenticatorRegister an authenticator
    Company IDOrganization ID 
    AccountCredential 
    Device Serial NumberBinding ID 

             

    Certification Details

    CAS

    Fortinet IPsec VPN

          

    Known Issues

    No known issues.