Skip to main content
FortiDor
Explorer II
July 21, 2025
Question

FortiClient IPSec-over-TCP - LDAP Users with email 2FA

  • July 21, 2025
  • 4 replies
  • 1048 views

Hello,

 

Is it possible to setup a email 2FA for LDAP users to protect the VPN IPSec-overs-TCP connection ? 
The feature is working fine in the SSL VPN as previously.

 

I found this KB but meaning working with a Certificat authentication : 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Using-email-based-MFA-with-certificate/ta-p/348005

 

My IPSec-over-TCP is working with a pre-shared key.

 

Thanks

4 replies

sjoshi
Staff
Staff
July 21, 2025

Yes it is possible.

You need to import the ldap user on the fortigate to assign 2fa

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Importing-LDAP-user-and-applying-two-factor-email/ta-p/195678

Thanks, Salon
FortiDor
FortiDorAuthor
Explorer II
July 21, 2025

Hello @sjoshi 

 

Already done but not working with the IPsec VPN instead of SSLVPN

 

Here is the information find in the ike log : 

> ike V=root:0:IPsec-TCP: EAP succeeded for user "xxx" group "XXX" 2FA=no

 

But in the user CLI setting : 

> config user local
edit "xxx"
set type ldap
set two-factor email
set email-to "xxx"
set ldap-server "COMMUN-AD"
next
end

 

Any information ?

sjoshi
Staff
Staff
July 21, 2025

can you show me the group config.

 

config user group

edit XXX

show

Thanks, Salon
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!