FortiClient SSL VPN Two-Factor Authentication with Active Directory Issue
Hi Everyone,
We are using the " FortiClient 6.0.9.0277 " version for remote connection with SSL VPN. User information comes from the Active Directory. After the connection is established, users need to do 2-Factor Authentication with SMS Verification. There is no any problem until that situation. If the username in the Active Directory is "lowercase" and the user tries to connect SSL VPN with "lowercase", verification SMS comes to the user's mobile phone. BUT, the username in the Active Directory is "lowercase" and the if the user tries to connect with any "UpperCase" or all "UPPERCASE" with using the true username, SMS does not come to the user's mobile phone. So, 2-Factor Authentication broke and the user done a perfect connection with using FortiClient SSL VPN. There must be any solution for that because it is a kind of HUGE BUG to pass the two-factor authentication security step. Also, the same situation occurs with using any non-English character using in a username. For instance, the user's name is Ömer, and the username in the Active Directory is defined as "omer" with using English characters. If the user enters the username in SSL VPN "ömer" or "OMER" or "Omer" or "ömer" or "omEr" it does not matter, again two-factor is passed easily.
Also, I found a similar problem continuing since 2012. Could you please inform me ASAP?
https://community.fortinet.com/t5/Fortinet-Forum/Two-Factor-auth-issue/m-p/58734#M58644
Best Regards
Emre