Skip to main content
HTGreg
New Member
November 24, 2022
Question

Correct Method for MSP Co-Management with MFA

  • November 24, 2022
  • 6 replies
  • 5440 views

As an MSP, we co-manage firewalls with in-house IT.   Combination of leased and customer owned appliances.  We have all customers in our FortiGate Cloud MSP edition instance.    Technicians are all setup with individual cloud accounts and forced MFA.   In-house IT takes the included tokens.  

 

For other systems, we have a shared MSP login with TOTP key entered into our password management system.   Password management is protected by individual logins with MFA.   IT Glue….   I believe this is pretty common.   

The problem lies in three spots.  

1.  We cannot add a FortiToken to any password management system.    We have to manually add/remove technicians.   This is a huge security blunder waiting to happen.   
2.   FortiTokens expense would get unreal.   We have many clients that are T&M.    We don’t get paid to have access, but when we get called, we need secure access.   
3.  Since the appliance must be registered with the primary forticloud account, we cannot MFA it.    Technicians need to be able to add appliances without waiting on the token holder to respond.   

We looked at FortiManager, but it was more designed for a single company applying policies over a large deployment.   Our clients are extremely different in needs.   As such, it is more effective to manage directly from the appliance.  

 

We tried doing the login via cloud; however, that only worked for the primary account.   

 

Many years ago, there was a forum post on asking TOTP abilities.    Yes, it is less secure; however, the barriers to implementation make the FortiGates less secure.   

What is the best method to address the following:

 

- enable MFA on the master account

- provide remote access logins for technicians.  

6 replies

gallon6341
New Member
November 25, 2022

Vakio bebe kokoa eto.

TPmat
New Member
March 2, 2023

Did you ever manage to find a proper solution for this? We're facing a similar issue ourselves and are looking into it.

BenGadget
Explorer
August 2, 2023

@HTGreg I also have this problem, did you ever figure out a solution?

gregbeason
New Member
March 1, 2024

Unfortunately, I never did find a solution.   Now my CEO wants to move us over to SonicWalls because the FortiGates are not protected.  

BenGadget
Explorer
March 1, 2024

@gregbeason 

Hey I did find a way.

We can use Azure SAML to do MFA for all of our administrator needs with our users, but let the client use the FortiTokens for MFA that come with the firewall.

gregbeason
New Member
March 1, 2024

Before I go down a Rabbit Hole, is SAML allowing you to not pre-add administrators?   Any chance you are working with Duo?  

I'm also assuming you are referring to this article.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configuring-SAML-SSO-login-for-FortiGate/ta-p/194656

TotalCareIT
Explorer
December 1, 2024

Is using Trusted hosts adequate? This has been a problem for over 2 years with no response from Fortinet. Make it useful with ITGlue seems to be an easy method. 

sjoshi
Staff
Staff
December 1, 2024

To address the challenges you are facing as an MSP managing multiple client firewalls, you can consider the following approach: Enable MFA on the master account by using FortiToken Cloud service, which offers a cost-effective and scalable solution for managing multifactor authentication. For providing remote access logins for technicians without relying on physical tokens, you can utilize FortiToken Mobile Tokens included in FortiToken Cloud, allowing technicians to authenticate securely using their mobile devices. This setup ensures strong security measures while offering flexibility and ease of access for your team members managing various client appliances.

Thanks, Salon