| Description | This article describes an issue with IKEv2 dial-up IPsec VPN where users authenticated through LDAP/EAP-TTLS are not receiving a token prompt and are able to connect without a token. |
| Scope | FortiOS 7.4. |
| Solution |
This issue can occur when a few key elements are in place:
An example configuration is provided below: config vpn ipsec phase1-interface edit "test"
set type dynamic
set interface "wan1"
set ike-version 2
set peertype any
set net-device disable
set mode-cfg enable
set eap enable
set eap-identity send-request
set ipv4-start-ip 10.212.50.200
set ipv4-end-ip 10.212.50.250
config firewall policy
edit 314
set name "vpn_test_remote_0"
set srcintf "test"
set dstintf "a"
set action accept
set srcaddr "test_range"
set dstaddr "dst_range"
set schedule "always"
set service "ALL"
set logtraffic all
set nat enable
set user test
next
end
config user local
edit "test"
set type ldap
set two-factor fortitoken
set fortitoken "FTKMOB03xxxxx"
set email-to xxx
set username-sensitivity disable
next
To troubleshoot, run the following debug commands and look for any errors indicating 'Token push is skipped , waiting for an auth_token request':
diagnose debug application ike -1 diagnose debug application fnbamd -1 diagnose debug enable [575] __group_match-Group 'test' passed group matching [239] fnbamd_comm_send_result-Sending result 7 (nid 0) for req 10630107074583, len=2641
To address this problem, EAP-TTLS token support has been added on FortiOS 7.4.9, 7.6.1 on FortiClient 7.4.4 and later versions.
Note: As per FortiClient v7.4.3 New Features, FortiClient 7.4.3 and above now support EAP-TTLS. The only way to enable EAP-TTLS for the free version of FortiClient (FortiClient VPN) is to change and then restore the XML configuration file. See Technical Tip: How to enable EAP-TTLS for IPsec IKEv2 tunnels in VPN-only (unlicensed) FortiClient.
Note: As of October 2025, FortiClient (Windows) 7.4.4 does not include an updated version of the free VPN-only agent. This is because no feature changes were made to the VPN-only agent between versions 7.4.3 and 7.4.4. Users can continue using the FortiClient 7.4.3 VPN-only agent: FortiClient 7.4.4 Special notices. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.