Skip to main content
Alperen_Uysal
New Member
July 13, 2020
Question

Fortigate SSL VPN with RSA SecurID as Multi-Factor-Authentication

  • July 13, 2020
  • 2 replies
  • 4935 views

Hey guys,

 

I have to implement RSA SecurID as Multi-Factor-Authentication. I found guides how to do that on FortiOS 5.6 but not with the actual one. Maybe someone of you had to do the same and can help me out with this or has a guide how to do that. All the guides use a local user bound to the RSA server but in my case I have a group that is bound to the AD with LDAP no local user. My problem is that I couldn't get it work that both of the authentication methods are used.

 

Thanks in advance!

 

 

2 replies

lobstercreed
New Member
July 13, 2020

I'm not familiar with RSA SecurID, but I assume the principles are largely the same as what we do with Okta.  Is RSA aware of your AD (i.e. can it do primary authentication)?  If so, you don't necessarily need "both", you just need the RSA server (RADIUS I assume?) to perform both factors before returning a successful login.

 

In our case specifically we use Aruba ClearPass (RADIUS) to authenticate all our SSL-VPN.  When we added Okta it was as simple as adding Okta RADIUS to ClearPass where password and MFA was checked, then ClearPass used whatever other AD attributes it needed to determine what groups to send back to the FortiGate.

 

I implemented on 6.0.9 though, and we're on 6.4.1 now.

Haiqua
New Member
October 22, 2020

I got the same problem. 

Follow this post.