SAML SSO with pre-authorized FortiGates
You can set up SAML SSO authentication in a Security Fabric environment by starting with a root FortiGate that has one or more pre-authorized FortiGates.
After the initial configuration, you can add more downstream FortiGates to the Security Fabric, and they are automatically configured with default values for a service provider.
To set up basic SAML SSO for the Security Fabric:
-
Log in to the root FortiGate of the Security Fabric.
-
Go to Security Fabric > Fabric Connectors and double-click the Security Fabric Setup card.
-
Join two pre-authorized FortiGates to the root FortiGate (see Configuring the root FortiGate and downstream FortiGates).
-
Configure the IdP (see Configuring the root FortiGate as the IdP).
-
Configure the SPs (see Configuring a downstream FortiGate as an SP).