Configuring single-sign-on in the Security Fabric
SAML SSO enables a single FortiGate device to act as the identify provider (IdP), while other FortiGate devices act as service providers (SP) and redirect logins to the IdP.
|
|
Only the root FortiGate can be the identity provider (IdP). The downstream FortiGates can be configured as service providers (SP). |
The process is as follows:
You can also use the CLI. See CLI commands for SAML SSO.