2FA SSL VPN with LDAP authentication
Hi all, i have a HA (active passive) pair of 100E fortigate firewalls and want to enable 2FA for SSL VPN.
Current Setup
We use LDAP auth, with any users in a specific AD group allowed to VPN in, saves us having to create individual users on the firewall.
2FA Setup
Two me it appears i can use either Fortitokens or a Certificate for 2FA, but from reading and testing it appears that for both methods i need to create local users mapped to LDAP users on the firewall. Then i can either apply a token or a cert to each user (LDAP or PKI), is my understanding correct?
Is there any way to enable 2FA without the need to create individual users on the firewall?
Thanks
