Description | This article describes the issue where the SSL VPN monitor in the FortiGate GUI displays that two-factor authentication is not enabled, despite the client successfully connecting to FortiGate using SSL VPN credentials and FortiToken without any errors. |
Scope | FortiGate, FortiClient. |
Solution |
This situation can occur when a user provides SSL VPN credentials (username+password) and tokens as concatenated. This is an expected behavior from FortiGate, as FortiGate cannot see the VPN users on SSL VPN as 2FA. (Attachment Below).
Note: If third party Two-Factor Authentication like Duo Security is implemented or the user does not have FortiToken enabled on the FortiGate, the Two-Factor Authentication for that user will show as 'disabled' on the FortiGate under the SSL VPN monitor. This is expected behavior. |