Skip to main content
tbarua
Staff
Staff
October 16, 2025

Technical Tip: How to resolve the 'EAP authentication failed due to missing token' error when using EAP-TTLS /PAP + 2FA Authentication

  • October 16, 2025
  • 0 replies
  • 6447 views

Description

This article describes how to resolve the EAP authentication failed due to missing token error while using EAP-TTLS/PAP with two-factor authentication in FortiAuthenticator.

Scope

FortiAuthenticator v6.6.3+, FortiGate, FortiClient. 

Solution

FortiClient added support for EAP-TTLS in IPsec VPN starting with version 7.4.3. FortiAuthenticator, as a RADIUS server, supports EAP-TTLS with PAP when using an IPsec IKEv2 tunnel.

 

  1. Enabling EAP-TTLS (EMS-Managed FortiClients).

The FortiClient documentation provides instructions on enabling EAP-TTLS support for EMS-managed FortiClients: EAP-TTLS support for IPsec VPN.

 

  1. Enabling EAP-TTLS (Unlicensed FortiClients).

For unlicensed (VPN-only) FortiClients, EAP-TTLS can be enabled by manually editing the configuration file.

Technical Tip: How to enable EAP-TTLS for IPSec IKEv2 tunnels in VPN-only (unlicensed) FortiClient.

 

Note that EAP-TTLS MFA support for LDAP users requires the following minimum firmware versions:

  • FortiOS v7.4.9, v7.6.1.

  • FortiClient Windows v7.4.4. Note the VPN-only free version of FortiClient Windows does not have a v7.4.4 release. See Special notices.

  1. FortiAuthenticator Configuration.

On FortiAuthenticator, allowed EAP types are configured under:

Authentication -> RADIUS Service -> Policies.

 

For more details, refer to: 

RADIUS Policies

 

Important:

When using FortiAuthenticator as a RADIUS server, the EAP-TTLS authentication tunnel from FortiClient terminates on FortiAuthenticator, not on FortiOS.

 

For additional technical details, see: Technical Tip: FortiOS IKEv2 EAP user authentication operation.

 

However, when using EAP-TTLS/PAP with two-factor authentication and FortiAuthenticator as the RADIUS server, the error EAP authentication failed due to missing token may appear in the FortiAuthenticator RADIUS logs.
For example:

 

(23) facauth: wad authenticate binding successful
(23) facauth: Remote LDAP user password authenticated
(23) facauth: Updated auth log 'abc@support' for attempt from 10.10.10.10~11.11.11.100: Remote LDAP administrator authentication partially done, expecting FortiToken 
(23) facauth: EAP authentication failed due to missing token. 
(23) # Executing group from file /usr/etc/raddb/sites-enabled/inner-tunnel
(23) } # server inner-tunnel
(23) Virtual server sending reply
(23) Message-Authenticator := 0x00
(23) eap_ttls: Got tunneled Access-Reject
(23) # Executing group from file /usr/etc/raddb/sites-enabled/default
(23) facauth: Updated auth log 'abc@support' for attempt from 10.10.10.10: 802.1x authentication failed

 
The two lines of interest in the output are:

(23) facauth: Updated auth log 'abc@support' for attempt from 10.10.10.10~11.11.11.100: Remote LDAP administrator authentication partially done, expecting FortiToken (23) facauth: EAP authentication failed due to missing token.

Additionally, no token prompt is displayed in FortiClient during the authentication process, and the authentication attempt fails with the following error message:


2b6c77b9.png


As of November 2025, no version of FortiAuthenticator supports challenge-based EAP-TTLS two-factor authentication (2FA).

 

As a workaround, users must use a concatenation token for EAP-TTLS 2FA, which combines the password and token. For example: p@ssw0rd345678.

 

In summary, if an LDAP user has 2FA enabled on FortiAuthenticator and is connecting to an IKEv2 VPN, they must:

  • Enter their username in the Username field.

  • Enter the password + token in the Password field.

 

Note:
Since an email or SMS token can only be received after entering the username and password, token concatenation for EAP-TTLS does not work with SMS or Email as a two-factor method. This also applies to FortiIdentity Cloud (formerly FortiTokenCloud) if it uses SMS or Email for 2FA.

 

Related documents:

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!