Skip to main content
feirrer
New Member
June 20, 2023
Question

Forced password change for SSL-VPN RADIUS user, doesn't show token field

  • June 20, 2023
  • 4 replies
  • 2182 views

Hi Everyone,

 

I got a problem with forced password change for new SSL-VPN users.

When entering the username and password, the next step should add a field to add the token, but one my primary it somehow doesn't show it, even tho I receive the token via SMS. It changed out of nowhere, worked fine previously, on my backup its still working correctly.

Anyone maybe had the same issue ?

 

This is how it looks like:

d7029e6b-5b74-4430-8db3-a5f8b3ff1265.png

 

Wrong2.png

 

 

This is how it should look like (my backup):

Correct1.pngCorrect2.png

4 replies

rbraha
Staff
Staff
June 21, 2023

Hi @feirrer 

Is there any FortiAuthenticator in place or just using FGT only ?

If using FAC , FAC needs to be joined to domain and Ldaps in place.

https://community.fortinet.com/t5/FortiAuthenticator/Technical-Tip-SSL-VPN-for-users-with-password-that-expire-using/ta-p/230543

 

If using FGT only ,also Ldaps is also required.

 

If the token filed is missing ,make sure that the correct users with token assigned are part of the groups added on SSLVPN Setting and also this group needs to be present on firewall policy.

 

 

feirrer
feirrerAuthor
New Member
June 21, 2023

Hi @rbraha 

 

Yes I'm using a FortiAuthenticator and I recently upgraded it to 6.4.6 firmware.

I'm using a RADIUS server, that has 2 clients 2200E and 500E.

With 500E which is on 7.X firmware works correctly, 2200E with 6.4.X firmware has a problem when the user doesnt specify the realm with username. 

 

On 500E there is only one realm, on 2200E there are 6 and on both "Use default realm when user-provide realm is different from all configured realms" is enabled.

 

Thanks for you reply.

 

rbraha
Staff
Staff
June 21, 2023

Hi @feirrer 

If having multiple realms on FAC ,its mandatory to specify the realm for users in a format specified on Radius policy username@realm, realm\username or realm/username

When the "Use default realm ... is enabled , FortiAuthenticator selects the default realm forauthentication when the user-specified realm is different from all
configured realm. Can you try to disable this option?

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!