Skip to main content
akileshc
Staff
Staff
September 21, 2020

Technical Tip: Allow two different groups with or without two factor authentication

  • September 21, 2020
  • 0 replies
  • 1367 views
Description
Users with and without 2 factor authentication enabled have to be able to authenticate using respective users.

This article describes how to allow this feature.

Solution
Network diagram.

FAC IP: 10.40.6.105
FGT IP: 10.40.4.123

On FortiAuthenticator configured the LDAP server and imported the users.






SMTP server configuration.





Enabling 2 factor authentication (email) for 'sslvpn1'.




Configure Group1.





Group2.




Configuring LDAP realm.





Configuring Radius client.





Configuring Radius policies.





SSLVPN configuration on FortiGate.





Configuring local groups.





Configuring SSLVPN portals.






Configuring SSLVPN settings.




Configuring SSLVPN policies.





Troubleshooting.

Login from SSLVPN1 where email 2 factor authentication is enabled.





Email FortiToken.




Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!