Skip to main content
Nea
Visitor III
December 23, 2025
Solved

VPN IPSec IKEv2 with ldap authentication + FortiToken : possible with the free VPN-only Client ?

  • December 23, 2025
  • 37 replies
  • 4415 views

Hello,

Seems we are forced to move from SSL to IPSEC VPN so we are actually trying it on our FTG901G v7.4.9

Our authentication is direct from the fortigate to Active Directory (ldaps)

It is working since we activated EAP-TTLS thank's to this trick : https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-enable-EAP-TTLS-for-IPSec-IKEv2-tunnels-in/ta-p/408602

 

BUT, it is not working when we add a FortiToken on the account

 

I saw on this page that 2FA is supported from client v7.4.4 with IKEv2 ldap users : https://community.fortinet.com/t5/FortiGate/Technical-Tip-Overview-of-compatible-IKE-versions-user/ta-p/420733

The little stars lead us to this Technical Tip and this Special Notice which explain that there is no free version of the 7.4.4 Forticlient, BUT the 7.4.3 free VPN-only agent is supposed to do the same job :

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Multi-Factor-Authentication-support-for-Windows/ta-p/407272

https://docs.fortinet.com/document/forticlient/7.4.4/windows-release-notes/683433/special-notices

 

I've read a lot of kb, tips and fortidocs but I'm still not sure to understand : are our FortiToken supposed to work in our situation ? :

VPN IPSec IKEv2 + ldaps auth (eap-ttls) + free VPN-only agent

Best answer by kwcheng__FTNT

Highly understood your concern.

The current version of free client should still remain but you might want to avoid expecting a new version for free client for now.

37 replies

funkylicious
SuperUser
SuperUser
December 23, 2025

hi,

have a look at https://community.fortinet.com/t5/FortiGate/Technical-Tip-Overview-of-compatible-IKE-versions-user/ta-p/420733 

how is the FortiToken assigned to the user ? locally on the FGT , on FortiAuth or using FortiIdentity Cloud ?

"jack of all trades, master of none"
Nea
NeaAuthor
Visitor III
December 23, 2025

Hi Funky,

FortiTokens are assigned locally on the FTG

funkylicious
SuperUser
SuperUser
December 24, 2025

then it should work in my opinion.

"jack of all trades, master of none"
yderek
Staff
Staff
December 28, 2025

@Nea  Isn't that you are using local user with MFA only ? Are you using EAP-TTLS  or just local user with MFA FortiTokens ?

Nea
NeaAuthor
Visitor III
December 28, 2025

The problem is with ldap users (EAP-TTLS since we are trying to move on IPSec)

With no Token : it is working

With the FortiTokens, it doesn't work : it isn't asking for the token

It results on Wrong credentials EAP fails (client side)

hpenmetsa
Staff
Staff
December 30, 2025

Hi, from the KB documents, it clearly mentions that for IKE v2 LDAP with MFA requires the FortiClient 7.4.4. As you are using FCT 7.4.3, it might not work.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Multi-Factor-Authentication-support-for-Windows/ta-p/407272#:~:text=FortiOS%20v7.4.9%2C%20v7.6.1.-,FortiClient%20Windows%20v7.4.4,-.%C2%A0Note%20the%20VPN

Nea
NeaAuthor
Visitor III
December 30, 2025

So, can you tell us if a new version of the VPN-only free FortiClient is coming soon?

Because currently, we are stuck on FortiOS version 7.4.9 since the SSL VPN disappears in 7.6 and the IPsec VPN does not work with our FortiTokens.

southwes12
New Member
December 30, 2025

Is does work. I have it working with 7.6.5 OS. Forticlient 7.4.4

 

Under IKE change Accepted peer ID to Specific peer ID. Put Remote in the space below. You will need to add it in you Forticlient side as well.

Also make sure Encryption - authentication only has AES128 - SHA256 and AES256 - SHA256 only list on firewall side only.

southwes12
New Member
December 30, 2025

The answer is yes. I am using it currently. The only thing that does not work is password changes on vpn logon. You would need to have your user change their password at least one day before, otherwise they cannot login. 

Fix for Free Forticlient How to enable EAP-TTLS for IPSec IKEv2 tu... - Fortinet Community

Nea
NeaAuthor
Visitor III
December 30, 2025

This fix allows an LDAP user to connect via IKEv2.

However, it doesn't work if you want to use a FortiToken with client 7.4.3.

southwes12
New Member
December 30, 2025

I think, i ran into the issue when i had the setting in phase1 with local id blank. I put in value Remote and also put in value on router side with Remote. Also phase 1 encryption set with only AES256-SHA256 and DH20 or DH21

southwes12
New Member
December 30, 2025

Also do not have these issues on the paid one.

southwes12
New Member
December 30, 2025

It may be the MFA was broken in 7.4.3.

Nea
NeaAuthor
Visitor III
January 7, 2026

I just edited the title of this post to add "with the free client"

 

We are still trying to know if there will be a new version of the VPN-only free client which will work with for IKEv2 vpn WITH our FortiTokens

 

The question is perhaps simply whether Fortinet will continue to maintain the VPN-only free client 

 

There is already at least one vulnerability that affects all versions of FortiOS 7.4.X : https://www.cve.org/CVERecord?id=CVE-2025-31514

That's why we would like to update to a mature 7.6 version

However, we have no solution for our VPN users on version 7.6, nor any visibility on a future solution.

 

We purchased over 200 Fortitokens in 2025 and we would like to know if we will be able to continue using them in future with the VPN-only free client.

kwcheng__FTNT
Staff
Staff
January 8, 2026

Hi

It is already stated that Forticlient 7.4.3 will not able to use Fortitoken on the KB which you had shared:

 

Using a FortiToken with EAP-TTLS is supported starting in v7.4.4. The free 7.4.3 FortiClient will be unable to connect if tokens are enabledTechnical Tip: Multi-Factor Authentication support for Windows FortiClient with LDAP (EAP-TTLS).

 

Nea
NeaAuthor
Visitor III
January 8, 2026

Okay, but can we expect a new version of the free FortiClient that will allow this?
Or will it never happen?

kwcheng__FTNT
Staff
Staff
January 8, 2026

No plan for Forticlient 7.4.4 free vpn only for now as there are no official announcement on this. You might want to find another alternative solution.

southwes12
New Member
January 8, 2026

7.4.9 OS requires some command line. 7.6.5 OS does not require command line. Forticlient ems 7.4.4 Works with 2fa, LDAP, & Fortitoken on router. 7.4.2 Free client does everything but requires IKEv1. You can use 7.4.3 free client but you will need to put the MFA code for fortitoken at the end of your password. Keep in mind you will need to do it fast before timeout on the fortitoken app.

forti13
New Member
January 19, 2026

Hi
I've the same issue VPN IKEv2 + EAP auth in LDAP only works without Fortitoken. I opend a ticket with Forti and here is its reply. 

 

Dear customer, Yes, there are official Fortinet Knowledge Base articles related to this behavior. Based on Fortinet official documentation, MFA support for IPsec IKEv2 connections depends on the FortiClient type being used, not only on the FortiGate configuration. Specifically, MFA for IKEv2 (including FortiToken or other MFA methods) is supported only with the full FortiClient managed by EMS, and not with the VPN Only client. The following official Fortinet KBs document this support scope:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Multi-Factor-Authentication-support-for-Windows/ta-p/407272 

https://community.fortinet.com/t5/Customer-Service/Technical-Tip-Technical-support-on-customization-on-various/ta-p/190989 

 These documents confirm that using IPsec IKEv2 with EAP-based authentication and MFA is not a supported combination when FortiClient VPN Only is used. For this reason, changing the MFA method will not resolve the issue unless the client type or access method is changed

Nea
NeaAuthor
Visitor III
January 19, 2026

Hello forti13,

Thanks for sharing.
We've reached the same conclusion.
Now we'd like Fortinet to tell us if they plan to release a new VPN-only client that will allow this configuration. We lack visibility and are stuck on FortiOS 7.4 because of this.

kwcheng__FTNT
Staff
Staff
January 20, 2026

No plan for now. You can raise this request to your local Fortinet Sales team.

southwes12
New Member
January 19, 2026

Have you tried setting up the fortitoken push on router to see if that works? Also try adding the 2fa token to the end of the user's password. Make sure to get it in before it expires.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!