Skip to main content
funkylicious
SuperUser
SuperUser
December 28, 2023
Solved

SSLVPN - FCT 2FA display message

  • December 28, 2023
  • 2 replies
  • 6143 views

Hello,

 

I was wondering if someone could shed some light on how the following can be achieved, if it can.

When 2FA is configured for users that are connecting to SSLVPN, that are either via RADIUS/FortiAuth/FortiToken or using a 3rd party OTP app, I noticed that you can change the banner message that is being displayed in FortiClient, specifically instead of the standard from below to a custom one:

 

Enter token code or no code to send a notification to your FortiToken Mobile

 

 

Can anyone point in the right direction on how to achieve this ? I searched in the Replacement Messages in FortiAuth and FortiGate, but couldnt find it.


Thank you.

Best answer by funkylicious

Unfortunately for the other SSLVPN profile, I dont have access to anything related to the configuration, just to the one of my company.

I saw those replacement msgs, but none have that exact specific message that I see. I might try and delete the default tag and insert some custom text and see what happens in the RADIUS Challenge Reply-Message with FortiToken Mobile Push .

 

L.E. Yep, that did the trick. The custom text I've inserted was visibile in FortiClient upon connecting to the SSLVPN.

2 replies

Toshi_Esumi
SuperUser
SuperUser
December 28, 2023

I would assume it must be in the FortiClient configuration under:

<system>

  <ui>

    <replacement_messages>

        .....(content).....

    </replacement_messages>

  </ui>

</system>

But I don't know the format/syntax to replace that particular message. Somebody from FTNT might have the internal info.

 

Toshi

funkylicious
SuperUser
SuperUser
December 28, 2023

I somehow doubt it, because I haven't changed anything and on a particular SSLVPN profile/connection the message is changed and when using others the default message is observed.

"jack of all trades, master of none"
Toshi_Esumi
SuperUser
SuperUser
December 28, 2023

It probably has multiple message types/attributes depending on the particular 2FA authenticator.

dbu
Staff
Staff
December 28, 2023

Hi @funkylicious ,

May be this can be done from FortiClient side ?  

Do you have a free VPN client or EMS license ?

 

funkylicious
SuperUser
SuperUser
December 28, 2023

Hi,

In my case, I use a free version of the client and have configured a SSL VPN connection which connects to a partner's FGT and which has 2FA with Google Authenticator and upon login that banner message in FortiClient is changed and it's being displayed in another language, other than EN and it's not the default one translated, while on other SSLVPN profile ( the one where I have RADIUS/FortiAuth and FTM ) I get the default message in EN.

"jack of all trades, master of none"
dbu
Staff
Staff
December 28, 2023

Just to clarify my understanding : 
You are using same Forticlient to connect with two different profiles and in one of them you are seeing this other language ? If yes, it sounds like a custom client. 
On the other side i believe that the free VPN client is not customizable.