Skip to main content
FortiNet_Newb
New Member
July 8, 2022
Question

FortiToken Mobile Push with IPsec VPN

  • July 8, 2022
  • 5 replies
  • 12057 views

Has anyone successfully setup FortiToken Mobile Push authentication with an IPsec VPN.  It works fine with a SSL VPN connection, but when using an IPsec VPN connection, you receive the push request, but Approving/Denying the request from the FortiToken app does nothing.  You are still able to login by providing the token manually (if you enter it BEFORE choosing Accept/Deny), but this behavior is confusing and a pain for our users.  Is it simply not supported by FortiNet yet?  It worked without issue with our older Cisco/DUO setup.  We are on the latest FortiClient 7.06 (doesn't work with previous versions either) and connecting to a FortiGate running FortiOS 7.06.  I see in the release notes for the newest FortiOS vs 7.2 that having ftm-push enabled does not allow IPsec VPNs to connect at all, so I don't want to update to 7.2 at this point.

 

Thanks!

5 replies

aahmadzada
Staff
Staff
July 9, 2022

Hello,
With the current design of the FortiOS and Forticlient app, the fortitoken mobile puh is not supported by Dialup IPSec.

 

For IPsec two-factor auth, we support mobile token, RSA token, Fortinet hardtoken, for these we need to enter the pin manually.


You can reach out to your local Fortinet Partner and submit an NFR(New Feature Request).

 

Ahmad

FortiNet_Newb
New Member
July 12, 2022

That’s unfortunate to hear it isn’t a feature already.  It makes no sense to me why the FortiGate would send ftm-push requests to dial-up IPsec clients if it is not a feature.  Is there anyway to at least configure ftm-push on the FortiGate to only send the push request to SSL VPN client requests, rather than the all or nothing approach?  We would still like to use the push feature for those connecting via SSL but disable it for the IPsec attempts, if possible (until it’s a feature that is added/supported).

Markus_M
Staff & Editor
Staff & Editor
July 12, 2022

Hello,

 

Do you have a RADIUS server like the FortiAuthenticator?

You could then create different RADIUS policies, one for SSLVPN users, matching a RADIUS Access request with value "vpn-ssl" and the attribute (forgot the exact name). The IPSec one will be different and not match. Disable push for the IPSec one.

To be sure, check the Fortiauthenticator debug logs at https://fac-ip/debug/radius (contains the access request and the name I am missing there).

 

Best regards,

 

Markus

blanosko
New Member
August 8, 2023

Hi, 

 

This would be maybe late for you but I just discovered this KB:

 

https://community.fortinet.com/t5/FortiAuthenticator/Technical-Tip-FortiToken-Push-on-FortiAuthenticator-operation/ta-p/190810

 

In the KB there is specific sentence:

 

5) Optionally: The user can,  instead of accepting the push notification, also simply enter the token code. FortiAuthenticator should receive this as another Access-Request, and accept the token code even if push notification has been initiated. This option might not be available if a user actively triggered push notification by sending an empty code or typing in 'push'.

 

I just tested it and it works. You can enable push notification in RADIUS policy (If you are using FAC as RADIUS server) and when trying to connect through IPSec VPN, you just type "push" instead of token and then you recieve push notification to mobile app and can aprove login that way. 

 

This is maybe not relevant for you but others will maybe find this useful, because everywhere on the internet you will find info that it is not possible to have push notif. working with IPSec VPN on FortiClient. Only weird thing is that I will not get the push notif. automaticaly when I enter credentials, I have to type push into token.

 

Tested on FGT 7.0.12, FAC 6.5.3, FCT 6.4.9

_Chris
New Member
November 20, 2025

Hello,

In response to the announcement that SSL-VPN will be discontinued, I am attempting to configure Push notifications with an IPSEC connection and I am encountering the same problem !

Has there been any news in the meantime?

firmware v7.2.12

Thank you in advance for your comments.

Chris

Markus_M
Staff & Editor
Staff & Editor
November 20, 2025

Hey Chris,

 

you've been digging to get to this old post, haven't you?

https://community.fortinet.com/t5/FortiGate/Technical-Tip-IPsec-dial-up-tunnel-using-IKEv2-with-FortiToken/ta-p/382760

 

Push notification over dial-up IKEv2 is supported only starting with FortiOS v7.2.8, v7.4.4, v7.6.0, and below FortiClient versions:      v7.2.4 and above for Windows.     v7.2.5 and above for MAC.     v7.2.5 and above for Linux. 

 

hope this helps.
https://docs.fortinet.com/document/forticlient/7.2.0/new-features/923380

I use IPsec VPN with FortiClient 7.4.4 on Linux and push works fine.

_Chris
New Member
November 24, 2025

Hi Markus,

Thank you for your reply!
I tried to configure it according to the links you provided, but unfortunately it doesn't work.
The problem seems to be that the users in the group are “Remote LDAP Users” and Fortigate does not accept this.
For now, the only solution I've found is to configure an IKE v1 tunnel with Xauth, but in this case, FortiToken Mobile Push authentication doesn't work.
As a reminder, it works perfectly with SSL-VPN.

Is there another solution, or should I just forget about FortiToken Mobile Push authentication in IPsec in my case?

Thank you.
Chris

lriese01
New Member
December 23, 2025

I had the same problem with ike1; ftm-push never worked, you had to enter the token manually. I have now switched to ike2 and it works:

- FG120xxxxxxxxxxx

- FW: v7.6.5 build3651

- Forticlient FREE: 7.4.3.6667

- Activate FTM + push on WAN1 incl. CLI: enable (see cli docu)

- Assign token to user (see documentation)

- install & Initialise on iPhone token app (see documentation)

ID 1 -8 was missing and not set correctly: important ID 2= localid = IP address from WAN1

- ID 9 and 10 are only necessary if you want to run multiple IPsec VPNs on WAN1 with different user groups or preshared keys (psksecret!

ike2-vpn-setting.jpg