Federation request is looping between the Authentication URL (redirect.jsp) and saml2sso URL.
Release: 12.8.x and 12.9
Component: Access Gateway
The Access Gateway agent was configured to use an ACO (Agent Configuration Object) that was not based on the SPSDefaultSettings ACO template. This can cause odd behavior around authentications that take place on the Access Gateway Web Agent.
The ACO used by the Access Gateway Agent should always be based on the SPSDefaultSettings ACO template.
Rebuilding the ACO based on this template to resolve the issue.