Skip to main content
kiri
Staff & Editor
Staff & Editor
August 28, 2025

Technical Tip: How to enable EAP-TTLS for IPSec IKEv2 tunnels in VPN-only (unlicensed) FortiClient

  • August 28, 2025
  • 4 replies
  • 33108 views

Description

This article describes how to enable EAP-TTLS as an authentication method in VPN-only (unlicensed) FortiClients.

Scope

FortiClient, EAP-TTLS authentication for IPsec VPN.

Solution

  1. EAP-TTLS Support in FortiClient.

FortiClient added support for EAP-TTLS authentication for IPsec VPN starting with version 7.4.3. This authentication method must be used when users need to authenticate to a remote LDAP server while connecting to an IPsec IKEv2 tunnel.

   

  1. FortiToken Compatibility.

Support for FortiToken with EAP-TTLS was introduced in FortiClient version 7.4.4. If FortiToken authentication is enabled, the free FortiClient version 7.4.3 will be unable to connect, as this version does not support multi-factor authentication with EAP-TTLS.


The following are the required firmware versions. Refer to Technical Tip: Multi-Factor Authentication support for Windows FortiClient with LDAP (EAP-TTLS).


EAP-TTLS MFA support requires the following minimum firmware versions:

  • FortiOS v7.4.9, v7.6.1.

  • FortiClient Windows v7.4.4. Note that the VPN-only free version of FortiClient Windows does not have a v7.4.4 release; see Special notices.
     

  1. Enabling EAP-TTLS.

  1. EMS-managed FortiClients.

FortiClient documentation outlines how to enable EAP-TTLS support for EMS-managed FortiClients here:

EAP-TTLS support for IPsec VPN

 

  1. Unlicensed FortiClients.

For unlicensed FortiClients, EAP-TTLS must be enabled by manually editing the FortiClient configuration file, which requires some familiarity with XML configuration.

 

  1. Prerequisites.

Before enabling EAP-TTLS, an IPsec IKEv2 tunnel should first be configured in FortiClient to match a dial-up configuration on the FortiGate.

Examples of configuration guides for IPsec IKEv2 dial-up tunnels include:


Once a VPN tunnel is configured on FortiClient, it can be edited to enable EAP-TTLS support.

 

  1. Export a FortiClient configuration backup.

fct_vpnonly_backup.png

 

  1. Edit the resulting *.conf file in an Editor like Wordpad, Notepad++, or similar.

  2. Find the section:

<vpn>
    <ipsecvpn>
         <connections>
             <connection>


There should be a connection listed with the name of the configured IPsec tunnel within this connection. Find the <ike_setting> part.

fct_vpnonly_conf.png

 

  1. In <ike_settings>, add the following line:

<eap_method>2</eap_method>


fct_vpnonly_conf_add_eap.png

 

Using 1: requires EAP-MSCHAPv2 authentication.
Using 2: requires EAP-TTLS/PAP authentication.


  1. Save the modified configuration as a separate file.

  2. Import the modified configuration into FortiClient. This may require the FortiClient to be unlocked.


fct_vpnonly_unlock.png

 

fct_vpnonly_restore.png

 

Important note:

At the time of writing, FortiClient iOS and Android do not support EAP-TTLS/PAP authentication.

 

EAP Method not saved in configuration backup:

Although the EAP method can be introduced by restoring a modified backup, FortiClient v7.4 does not save the EAP Method value in the configuration backup. If a FortiClient backup is taken from a FortiClient with EAP-TTLS enabled and restored to a different FortiClient without modification, the new FortiClient will not have EAP-TTLS enabled.

 

Verifying the EAP method via the registry editor:

The current EAP method for a tunnel can be viewed in the Registry Editor by navigating to 'HKEY_LOCAL_MACHINE\SOFTWARE\Fortinet\FortiClient\IPSEC\Tunnels\<TunnelName>\P1\eap_method'.

 

  • If the eap_method value is 1, the tunnel uses EAP-MSCHAPv2.

  • If the eap_method value is 2, the tunnel uses EAP-TTLS.

 

nkorea_2-1773519890333.png

 

Related documents:

    4 replies

    Explorer
    June 4, 2026

    Why are we keeping this janky config?

    Adding just a checkmark on the UI?

    RolandBaumgaertner72
    New Member
    June 11, 2026

    Not working. I changed the XML, the registry was OK already and with LDAP WITHOUT MFA it works (also it works with local user) but activating MFA I get the old EAP failure.

     

    Any othe ideas? I mean, this IPsec IKEv2 + LDAP + MFA with Forticlient EMS would work 100%??

     

    Thanks!

    Explorer
    June 11, 2026

    Im not sure about a LDAP MFA or Fortigate MFA? Maybe it doesn’t work with LDAP MFA, it does work with Fortigate tokens

     

    RolandBaumgaertner72
    New Member
    June 11, 2026

    I just tried, Forticlient 7.4.3, FG80F with 7.6.6, IPsec IKEv2 and Users from LDAP and MFA Fortitoken enabled. The user without MFA enabled works fine but this is not our scope since we used SSL VPN with LDAP Users and FortiToken

    Explorer
    June 11, 2026

    Show your debug please

    !-->

    diagnose debug reset
    diagnose debug disable
    diagnose debug application ike -1
    diagnose debug enable
    Staff
    June 30, 2026

    LDAP + MFA is not supported in the free VPN only. It requires FCT 7.4.4 and above, which needs license. See this article. 


    If centralized management with EMS is not needed, only VPN connection, you can go for the new “FortiClient Standalone Edition”. 


    “FortiClient Standalone is an entry-level commercial tier designed for small-scale deployments that do not require centralized Endpoint Management Server (EMS). It provides essential remote access VPN with MFA support and FortiIdentity Cloud Basic subscription, alongside technical support via email. The standalone FortiClient is ideal for small businesses or free VPN users looking for a low cost officially supported FortiClient.”  

    https://www.fortinet.com/support/product-downloads