Skip to main content
21546533Gmail
New Member
September 5, 2025
Question

Dialup IPSec IKEv2 VPN Config using Duo Proxy and NPS

  • September 5, 2025
  • 1 reply
  • 977 views

We are looking to migrate to an IKEv2 Dialup VPN with Duo Proxy for MFA and integrating with NPS.  Does anyone have a working config they can provide for this configuration?  I can't seem to find anything online.

1 reply

Markus_M
Staff & Editor
Staff & Editor
September 7, 2025

What protocol is the Dou Proxy proxying? LDAP or RADIUS?
If RADIUS - this should work:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-IKEv2-Dialup-IPsec-tunnel-with-RADIUS-and/ta-p/220818 - DUO being a proxy should basically only mean that your server on FortiGate would be DUO and on DOU the target would be NPS. After authentication success against NPS, DOU would ask for a second factor. Once answered, DUO would respond to FortiGate as the RADIUS server.