Skip to main content
pksubramanian
Staff
Staff
September 3, 2019

Technical Tip: Enabling Two Factor PUSH Authentication on FortiAuthenticator

  • September 3, 2019
  • 0 replies
  • 1849 views

Description

This article describes how to enable PUSH Authentication instead of entering the token code manually.


Solution

1) The interface that receives the approve/deny FTM push responses must have the FortiToken Mobile API service enabled.

 

matanaskovic_0-1637272354279.png

 

 

2) Enter the network public IP address under System -> Administration -> System Access -> Public IP/FQDN for FortiToken Mobile:

matanaskovic_1-1637272354298.png

 

 

FortiAuthenticator only listens on port 443. NOTE: If the FortiAuthenticator interface is configured with a Private IP then it may be needed to NAT the Public->Private for that IP.

 

3) Make sure to enable through RADIUS policy in the Authentication factors > Advanced options > Allow FortiToken Mobile push notifications.

 

matanaskovic_2-1637272354308.png

 

 

Related Article:

https://docs.fortinet.com/document/fortiauthenticator/6.4.0/cookbook/125367/configure-two-factor-authentication-on-fortiauthenticator