FortiAuthenticator
FortiAuthenticator provides centralized authentication services for the Fortinet Security Fabric including multi-factor authentication, single sign-on services, certificate management, and guest management.
Nivedha
Staff
Staff
Article Id 331790
Description This article describes the process flow when FortiAuthenticator is configured as a RADIUS Server and FortiToken push notification is enabled for SSL VPN users.
Scope FortiAuthenticator All models.
Solution

FortiAuthenticator can be configured as a RADIUS server for SSL VPN users as describes in the following document: SSL VPN with RADIUS on FortiAuthenticator.

Operational flow details are explained in Technical Tip: FortiToken Push on FortiAuthenticator: operation flow and details.

The diagram below explains the flow for the SSL VPN client.

Note: The following prerequisites are required for the flow to work:

 

  1. The Remote Client should have internet access and have connectivity to FortiGate (SSL VPN server).
  2. FortiGate is added as the RADIUS Client on FortiAuthenticator and FortiAuthenticator as the RADIUS Server on FortiGate.
  3. FortiAuthenticator can reach the DC (LDAP server) and LDAP users are imported and assigned a token.
  4. FortiAuthenticator can reach to push.fortinet.com.
  5. FortiToken assigned to the user is activated either by scanning the QR code provided to the user or by adding the invite code to the FortiToken Mobile app.

    FAC - Simulations-SSLVPN FAC as RADIUS Mobile token push.drawio.png