Technical Tip: How to enable EAP-TTLS for IPSec IKEv2 tunnels in VPN-only (unlicensed) FortiClient
Description | This article describes how to enable EAP-TTLS as an authentication method in VPN-only (unlicensed) FortiClients. |
Scope | FortiClient, EAP-TTLS authentication for IPsec VPN. |
Solution |
FortiClient added support for EAP-TTLS authentication for IPsec VPN starting with version 7.4.3. This authentication method must be used when users need to authenticate to a remote LDAP server while connecting to an IPsec IKEv2 tunnel.
Support for FortiToken with EAP-TTLS was introduced in FortiClient version 7.4.4. If FortiToken authentication is enabled, the free FortiClient version 7.4.3 will be unable to connect, as this version does not support multi-factor authentication with EAP-TTLS.
FortiClient documentation outlines how to enable EAP-TTLS support for EMS-managed FortiClients here: EAP-TTLS support for IPsec VPN
For unlicensed FortiClients, EAP-TTLS must be enabled by manually editing the FortiClient configuration file, which requires some familiarity with XML configuration.
Before enabling EAP-TTLS, an IPsec IKEv2 tunnel should first be configured in FortiClient to match a dial-up configuration on the FortiGate. Examples of configuration guides for IPsec IKEv2 dial-up tunnels include:
![]()
![]()
![]()
Using 1: requires EAP-MSCHAPv2 authentication.
![]()
![]()
Important note: At the time of writing, FortiClient iOS and Android do not support EAP-TTLS/PAP authentication.
EAP Method not saved in configuration backup: Although the EAP method can be introduced by restoring a modified backup, FortiClient v7.4 does not save the EAP Method value in the configuration backup. If a FortiClient backup is taken from a FortiClient with EAP-TTLS enabled and restored to a different FortiClient without modification, the new FortiClient will not have EAP-TTLS enabled.
Verifying the EAP method via the registry editor: The current EAP method for a tunnel can be viewed in the Registry Editor by navigating to 'HKEY_LOCAL_MACHINE\SOFTWARE\Fortinet\FortiClient\IPSEC\Tunnels\<TunnelName>\P1\eap_method'.
![]()
Related documents: |






