Question
SSL VPN MFA autentification
There are new requirement from PCI DSS, that MFA autentification verification, should be done after all factors were submited.
At the moment fortigate SSL VPN client first asks for user name and password, and if they are correct, only then asks for fortitoken code. It should ask for user name, password, and fortitoken code, and only then accept or deny. So that user could not know which part of MFA was wrong.
Also it would be great if we could use the same fortitokens for administrators logon to device using MFA autentification.
