FORTIGATE - SAML Debug

From IT-Arts.net
Revision as of 06:55, 6 July 2026 by Admin (talk | contribs)


Return to Wiki Index

Debug SAML Authentication

Enable timestamped debugging

Enable timestamps before collecting any debug output to simplify correlation with client and identity provider logs.

diagnose debug console timestamp enable
diagnose debug reset
diagnose debug application samld -1
diagnose debug application fnbamd -1
diagnose debug enable

Disable debugging

Always disable debugging after troubleshooting to avoid unnecessary CPU usage and excessive log generation.

diagnose debug disable
diagnose debug reset

Verify SAML daemon activity

Check that SAML daemon is actually processing authentication requests.

diagnose sys process pidof samld
diagnose sys top

SAML Runtime Information

Display current SAML sessions

diagnose vpn ssl saml-session list

Example:

Session ID : 9
User       : john.doe
Group      : VPN_Users
Portal     : full-access
IdP        : AzureAD
Login time : 2026-07-04 09:54:13

Display authenticated users

diagnose firewall auth list

Display session table

diagnose sys session list

SSL VPN Debugging (SAML + non-SAML)

Enable SSL VPN debug

diagnose debug application sslvpn -1
diagnose debug enable

View SSL VPN sessions

get vpn ssl monitor

SSL VPN configuration check

show vpn ssl settings

IPsec SAML / authentication context (important)

SAML is typically used for SSL-VPN, but in IPsec environments authentication depends on mode:

IPsec with username/password (FNBAMD path)

Authentication is handled by fnbamd (same as SAML group mapping logic).

diagnose debug application fnbamd -1
diagnose debug application ike -1
diagnose debug enable

The IPsec Case

IKE Gateway State (Primary Equivalent)

This is the closest equivalent to “who is connected” in IPsec.

diagnose vpn ike gateway list

Provides:

  • Peer IP address
  • Authentication method (PSK / certificate / EAP)
  • IKE SA state (up/down)
  • Negotiation status
  • Lifetime information

Use this as the primary “session-like” view for IPsec.

IPsec Tunnel State (Data Plane View)

Shows active encrypted tunnels and traffic selectors.

diagnose vpn tunnel list

Provides:

  • Active Phase 2 SAs
  • Encryption domains (subnets)
  • SPI values
  • Traffic counters
  • Tunnel up/down state

This is equivalent to “active VPN data sessions”.

Summary View

Quick overview of active IPsec tunnels:

get vpn ipsec tunnel summary

Provides:

  • Tunnel name
  • Status (up/down)
  • Quick health visibility

User Identity in IPsec (When It Exists)

IPsec only shows user identity when authentication is user-based.

EAP / RADIUS / LDAP authentication

In this case, identity is handled by fnbamd:

diagnose firewall auth list

or deeper inspection:

diagnose debug application fnbamd -1

This may show:

  • Username
  • Group membership
  • Authentication source
  • Authorization result

IPsec tunnel negotiation debugging

diagnose debug application ike -1
diagnose vpn ike gateway list
diagnose vpn tunnel list

Live IKE negotiation trace

diagnose debug console timestamp enable
diagnose debug reset
diagnose debug application ike -1
diagnose debug enable

Filter by peer IP:

diagnose vpn ike log-filter addr <peer_ip>

Stop debug:

diagnose debug disable
diagnose debug reset

IPsec + SAML reality check

SAML is NOT directly used in classic IPsec tunnels.

Instead:

  • SSL-VPN → SAML supported natively
  • IPsec dialup → usually LDAP/RADIUS or local users
  • IPsec + external auth → goes through fnbamd, not samld

So when troubleshooting IPsec login issues, focus on:

  • ike daemon
  • fnbamd daemon
  • user/group mapping

Web authentication (shared backend)

diagnose debug application fnbamd -1
diagnose debug enable

Useful for:

  • SAML group mapping
  • LDAP / RADIUS fallback
  • user identity resolution

Certificates validation

show full-configuration vpn certificate local
show full-configuration vpn certificate ca

Time synchronization (critical for SAML)

get system status
diagnose sys ntp status

Packet capture (SAML / IPsec)

SAML / HTTPS

diagnose sniffer packet any "host <idp_ip>" 4 0 a

IPsec IKE

diagnose sniffer packet any "udp port 500 or udp port 4500" 4 0 a

Flow debugging (authentication path)

diagnose debug reset
diagnose debug flow filter clear
diagnose debug flow show function-name enable
diagnose debug flow trace start 100
diagnose debug enable

Filter:

diagnose debug flow filter addr <client_ip>

Stop:

diagnose debug disable
diagnose debug reset

Common failures

SAML login loop

  • wrong ACS URL
  • cookie blocked
  • time drift
  • wrong entity-id

IPsec authentication fails

  • wrong group mapping
  • fnbamd rejection
  • phase1 mismatch
  • PSK mismatch (non-SAML case)

SAML works but no VPN access

  • firewall policy missing
  • group not mapped
  • portal mismatch

No debug output

  • forgot enable
  • wrong daemon targeted
  • authentication not triggered

Security concepts

Assertion integrity

SAML must be signed and validated.

Trust chain

Only trusted IdP certificates allowed.

Time validation

NTP drift breaks authentication.

Least privilege

Map only required groups to VPN access.


Return to Wiki Index