What triggers the email to be sent by FortiAuthenticator for users that receive token via email?
Please try to stay with me on this longer post... I've tried to shorten it up but there is a lot to relay on this one and I appreciate your taking the time and reading through it.. First off, Let me elaborate on that Subject a little.
My user is currently configured to receive a token into my email account when I do things such as: log into any of our Gates, Connect to IPSEC VPN's, Log into our VMware Horizon virtual desktops, etc... I am receiving the token via a RADIUS Client on the FA where the authentication group ultimately looks at our AD environment via LDAP and/or FSSO so I can use the same credentials across several platforms.
This works fine with the exception of an occasional delay in the SMTP conversation(s) which will occasionally cause the login to timeout before I can get the token input - Other than that, I have been using this method w/o issue for a couple of months now BUT most everyone in the company are using FortiToken Mobile.
I was recently tasked with getting our Ironport SPAM and AV box to participate in 2FA for the admin account logins. It has a config section for RADIUS (and LDAP) but my boss for whatever reason wants to use the local accounts on Ironport over the LDAP we use most everywhere else.
In testing I can get the Ironport to prompt me for the token but I never receive the taken into my email so I have nothing to enter in there. When troubleshooting and looking at a PCAP on our Gate that is directly connected to Ironport, I do not see the Ironport attempt to communicate with FA until I input some random numbers (Recall that I never got a token in email to input) and hit "login" which obviously....
So my question(s) go back to:
1. What event triggers that email to be sent from FA to the user when they are wanting to use a device protected by that realm via 2FA and FA? The FSSO/LDAP?
2. Can you use the token to email when using only the RADIUS client on FA?
Apologies for long post.
dt
