This article describes the use of email tokens, which are commonly adopted as an initial step to enhance security for remote VPN or administration on FortiGate devices as detailed in Technical Tip: Importing LDAP user and applying two factor email Token and Technical Tip: Email Two-Factor Authentication on FortiGate.
A common challenge in large deployments is how to automatically import and manage LDAP users with FortiGate.
FortiGate, Remote user access.
Two-Factor Authentication (2FA) or Multi-Factor Authentication (MFA) should be a requirement in any deployment and stronger and more secure methods should be preferable whenever possible.
Preferable methods:
Less preferable methods:
On FortiGate devices, each user must be manually mapped to an email address to retrieve the email token, as group-based automation for this process is currently unsupported. This manual mapping requirement can significantly increase administrative overhead in large deployments, where automating configurations is crucial for efficiency and scalability.
Options to Escalate and Automate Deployment:
2. External Identity Provider (IDP) via SAML:
Related documents:
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.