VPN IPSec IKEv2 with ldap authentication + FortiToken : possible with the free VPN-only Client ?
Hello,
Seems we are forced to move from SSL to IPSEC VPN so we are actually trying it on our FTG901G v7.4.9
Our authentication is direct from the fortigate to Active Directory (ldaps)
It is working since we activated EAP-TTLS thank's to this trick : https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-enable-EAP-TTLS-for-IPSec-IKEv2-tunnels-in/ta-p/408602
BUT, it is not working when we add a FortiToken on the account
I saw on this page that 2FA is supported from client v7.4.4 with IKEv2 ldap users : https://community.fortinet.com/t5/FortiGate/Technical-Tip-Overview-of-compatible-IKE-versions-user/ta-p/420733
The little stars lead us to this Technical Tip and this Special Notice which explain that there is no free version of the 7.4.4 Forticlient, BUT the 7.4.3 free VPN-only agent is supposed to do the same job :
https://docs.fortinet.com/document/forticlient/7.4.4/windows-release-notes/683433/special-notices
I've read a lot of kb, tips and fortidocs but I'm still not sure to understand : are our FortiToken supposed to work in our situation ? :
VPN IPSec IKEv2 + ldaps auth (eap-ttls) + free VPN-only agent
