Skip to main content
Tutek_OLD
New Member
June 23, 2020
Question

SSL VPN with Windows NPS and e-mail 2FA

  • June 23, 2020
  • 3 replies
  • 4016 views

Could anyone help me configure on Forti 100F SSL VPN (only tunnel mode) with authentication on Windows 2012 R2 NPS and e-mail based 2FA? I already connected FGT with Windows Server, created NPS policy, created VPN-Users group with couple users inside. But what next, how to configure e-mail 2FA for radius users that are on Windows server?

    3 replies

    Tutek_OLD
    Tutek_OLDAuthor
    New Member
    June 23, 2020

    I can successfully authenticate using radius NPS and connect using SSL VPN, but I do not have additional box with e-mail token to enter (I use latest forticlient vpn). I would rather to use SSL VPN as this have additional host-checks, standard IPSEC VPN do not have such features.

    Tutek_OLD
    Tutek_OLDAuthor
    New Member
    June 25, 2020

    why there is so weak support on this forum[&:] ?

    I've done this, corresponding local user as radius user needs to be created, then assigned to local group, and then in firewall policy as source this group should be choosen. 

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!