Skip to main content
vinceneil666
New Member
May 4, 2018
Question

FortiGate two factor authentication, sms and ldap

  • May 4, 2018
  • 2 replies
  • 6585 views

Hi,

I would like my SSL VPN users to have two factor authentication when connecting.

 

I have the VPN working fine with regular LDAP authenticatoin, but when I know want to add the "other factor" ..Im a bit lost.

Do I understand it correctly that within my Fortigate SSL VPN configuration, I am not able to add both my LDAP auth and my RADIUS auth (the radius is my sms thingy..Mideye).

 

I might need to run everything trough a Radius server ( I have a NPS running ) and have the 2factor happen there ? 

 

Its not possible to add both LDAP and RADIUS auth to my SSL config on the fortigate ? or ? 

    2 replies

    Fishbone_FTNT
    Staff
    Staff
    May 23, 2018

    Hi,

    no,  you can't do both RADIUS and LDAP,  Fortigate doesn't have any chained-like authentication.

    I guess Mideye has its own RADIUS server which integrates into your LDAP. This RADIUS server should be then used in Fortigate configuration.

    This is the way I would investigate.

     

    Regards,

    Fishbone)(

     

     

    Uwe_Sommerfeld
    New Member
    May 23, 2018

    If I remember correctly the supported second factor for SSL VPN is certificate based only. So trust your personal CA and deliver certificates to the users. 

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!