Skip to main content
RW2
New Member
November 25, 2025
Question

IKEV2 + LDAP + MFA

  • November 25, 2025
  • 2 replies
  • 578 views

Hi, 

We have recently understood that IKEV1 is being phased out and we are currently studying IKEV2 for our IPSEC Dialup connections.

We are a Windows house so we will be using LDAP for our users and I would like to know if anyone can provide feedback about which MFA or 2FA they are using and any associated problems.

I have seen varying information that stated that if we use EAP-MSCHAPV2 we cannot use FortiToken with LDAP accounts.  And if we use EAP-TTLS we must have EMS licences but Fortitokens might still be possible.

Can someone confirm which setup the have successfully setup, it must be a LDAP setup and which MFA they are using and any roadblocks that they have come across.

Cheers 

2 replies

funkylicious
SuperUser
SuperUser
November 25, 2025
tbarua
Staff
Staff
November 25, 2025

Hi RW2,

FortiClient added support for EAP-TTLS & LDAP in IPSec VPN starting in version 7.4.3. 

You can configure it using the <eap_method> option in the XML configuration , 

https://docs.fortinet.com/document/forticlient/7.4.0/new-features/907253/eap-ttls-support-for-ipsec-vpn-7-4-3

However, as per one of the known issues 1031789 ,  Windows FCT 7.4.3 does not support IPsec IKEv2 EAP-TTLS 2FA, but should be supported in 7.4.4 and FGT 7.4.9. 

 

Best regards,