Skip to main content
RolandBaumgaertner72
New Member
June 11, 2026
Question

SOLUTION for IPsec IKEv2 + LDAP + Fortitoken VPN Only PLEASE

  • June 11, 2026
  • 1 reply
  • 143 views

Hi,

I have been following the KB articles and forum comments for months, but I still don’t see a workable solution for us.


We are using a FG90G (FortiOS 7.4.7) with SSL VPN, around 100 LDAP users, FortiClient VPN-only, and FortiToken for MFA. This setup worked very well for many years, but due to OS-related requirements, we now need to move to a new solution.


First, we configured IPSec IKEv1 with around 10 of our LDAP users. Some of them work fine, but others experience significant issues, mainly frequent disconnections — approximately 1–2 disconnects per hour. With 100 users, this is not a viable long-term solution.

 

We then tested IKEv2 on a FG80F. It works fine with local users + FortiToken, but with LDAP + FortiToken + FortiClient VPN-only, we receive an EAP failure message. I’m not sure whether there is a proper solution via FortiClient XML configuration that could resolve this, or whether there are other limitations we are facing.


A more drastic option would be to replace the FG90G with a FG100F that we currently have in our warehouse. However, I am unsure whether we can transfer the existing 100 FortiTokens (I don’t remember when they were originally purchased).


At this point, can anyone suggest a realistic and stable solution that we can implement? We already have several open tickets with support, but so far we do not have a working solution.

Thanks!!!

1 reply

funkylicious
SuperUser
SuperUser
June 11, 2026

maybe these articles will help you for IKEv2 w/ LDAP + MFA . you would need to test by editing the XML config file with the eap_method set to 2 and see if it solves your issue, should do that.

"jack of all trades, master of none"