Technical Tip: FortiOS IKEv2 dial-up VPN user and Multi-Factor Authentication resources
Description
This article provides an overview of guides and resources for User and Multi-Factor authentication in FortiOS IKEv2 Dial-up IPsec VPN.
Scope
FortiOS v7 and later.
Solution
Determine the user source and required MFA method(s) and refer to the table below.
Â
Â
User sources:
Active Directory: Windows Active Directory, third-party LDAP, Azure AD, or Entra Connect.
Remote RADIUS: User credentials stored on FortiAuthenticator or authenticated against a third-party RADIUS server.
Local FortiGate Users: Users with credentials stored on FortiGate.
Entra ID: User credentials exist only in Entra and cannot be authenticated using Active Directory methods.
SSO: FortiGate IPsec as SAML SP to an external SAML IDP. External SAML IDPs include Entra ID, Google Workspace, and FortiIdentity Cloud as local or proxy IDPs.
If multiple user sources are required, it may be necessary to leverage network-id to configure multiple remote gateways. See the following articles:
MFA methods:
FortiToken: FortiIdentity Cloud, FortiToken Mobile, hardware FortiToken. One-time password (OTP) entry in FortiClient. On supported FortiOS versions, FortiIdentity Cloud and FortiToken Mobile also support push authentication using the FortiToken Mobile app.
E-mail/SMS: FortiGate or FortiAuthenticator delivers the OTP to the user's configured e-mail address or phone number using e-mail or SMS. User enters OTP on FortiClient, similar to FortiToken use cases.
IKE gateway certificate authentication: Authenticating to FortiOS dialup gateway using a client certificate rather than a pre-shared key. Considered a form of MFA if the client certificates are only installed on particular devices.
Third-party: Any MFA method triggered on a non-Fortinet authentication product. Includes DUO, Entra MFA, Google Authenticator and other methods. FortiGate has no visibility on these MFA methods; from FortiGate's perspective, third-party MFA is simply unusually slow remote authentication.
Note:
IKEv2 dial-up IPsec VPN is the recommended alternative to FortiOS SSL VPN tunnel mode, and IKEv2 is recommended over IKEv1 for most new FortiOS remote access VPN deployments. See SSL VPN tunnel mode to IPsec VPN migration.
Related articles:
Â
Agentless remote access resources:
