FortiManager 7.2.1 - SAML My Page SSO Configuration RSA Ready Implementation Guide
Originally Published: 2023-03-24
This section describes how to integrate FortiManager with RSA Cloud Authentication Service using My Page SSO.
Procedure
- Sign into the RSA Cloud Console and go to Applications > Application Catalog > Create From Template > SAML Direct.
- Select Cloud in the Choose where to enable your application section and select Next Step.
- Go to the FortiManager System Settings > Admin > SAML SSO and select Service Provider (SP) tab as Single Sign-On Mode.
- In the IdP Settings, select Custom tab, then fill in the IdP Entity ID and IdP Login URL from the Identity Provider URL found from the Application > Connection Profile that was done in the previous step.
- You can choose to automatically create a new user after successful authentication or not from the Auto Create Admin option on the FortiManager SAML SSO page.
- For the IdP logout URL, add it as the https://FQDN of your FortiManager.
- For the IdP Certificate, choose the certificate file from the RSA Cloud Console, whether you have chosen the default certificate or uploaded a new one, it is to be uploaded here to validate the SAML responses sent from RSA.
Note: You can choose to Sign Assertion only or Sign entrie SAML response according to your implementation. - In the User Identity section, use NameID as unspecified and property as mail. You must send attribute statement for the FortiManager, it should be username and map it to mail.
- If you have chosen SP-Initiated flow, ensure at the top of the page that the Connection URL is added as the SP ACS (login) URL.
- If you have chosen IdP-initiated flow, ensure to add this input in the Relay State parameter at the bottom of the page.
- Select the Show Advanced Configuration dropdown and under the User Identity section, select your desired policy to be applied, then select Next Step > Save and Finish > Publish Changes.
- Under the Portal Display page, if needed, select Display in Portal as FortiManager supports IdP initiated SAML SSO.
Configuration is complete.
Return to the main page.
Related Articles
Salesforce - SAML My Page SSO Configuration - RSA Ready Implementation Guide 75Number of Views Palo Alto NGFW Global Protect - SAML My Page SSO Configuration - RSA Ready Implementation Guide 56Number of Views Microsoft Entra ID - SAML My Page SSO Configuration - RSA Ready Implementation Guide 218Number of Views AWS IAM Identity Center - SAML My Page SSO Configuration - RSA Ready Implementation Guide 20Number of Views FortiGate Firewall - SAML My Page SSO Configuration Using SSL VPN - RSA Ready Implementation Guide 25Number of Views
Don't see what you're looking for?