FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
jhussain_FTNT
Article Id 414362
Description This article describes how to configure GUI access of FortiGate with remote user group using FortiAuthenticator as the radius server and allowing access with and without 2FA when accessing inside and outside the network for the same user.
Scope FortiGate, FortiAuthenticator.
Solution

FortiGate:

  1. Configure the radius server with FortiAuthenticator.

image.png

 

  1. Configure the user group under User & Authentication -> User Groups.

image.png

 

  1. Configure the Admin profile with a remote server group under System -> Administrator and select the user group in the Remote user group setting.

image.png

 

FortiAuthenticator:

  1. Assign LDAP user with FortiToken and add the user to the user group.

image.png

 

  1. Configure Trusted subnet (e.g. a local LAN network subnet) under Authentication -> User Account Policies -> Trusted subnets.

image.png

 

  1. Create a new rule under Authentication -> User Account Policies -> Adaptive MFA Rules and add the Pre-defined trusted subnet.

image.png

 

  1. Apply the Adaptive MFA rule in the RADIUS policy profile.
 

image.png

 

When the user tries to connect to FortiGate GUI from  outside network 

 

image.png

 

image.png

 

When the user tries to connect to the FortiGate GUI by accessing a local network, the user is able to log in without a FortiToken.

 

image.png