Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
R_F
Contributor

ZTNA with 2FA

is there any use case wherein I can integrate 2FA with ZTNA?

Current setup we are using SSL VPN to access our internal resources such as RDP. SSL VPN users tied up to FToken.

Now we want to explore how the ZTNA works. Cant figure out how to maintain 2FA without SSL VPN and through ZTNA my staff could access our internal resources.

1 Solution
Debbie_FTNT
Staff
Staff

Hey R_F,

you have essentially two options to integrate 2FA with ZTNA setup:

-> you can do a SAML authentication against a FortiAuthenticator, for example, which would then prompt for the token code

-> you could do form-based authentication (basic does not support two-factor authentication)

-> you might have to enable two-factor authentication in the proxy authentication rule (via CLI)

For example:

https://docs.fortinet.com/document/fortigate/7.0.0/new-features/591056/ztna-session-based-form-authe...

https://docs.fortinet.com/document/fortigate/7.0.0/new-features/461532/ztna-proxy-access-with-saml-a...

I hope this helps :)

+++ Divide by Cucumber Error. Please Reinstall Universe and Reboot +++

View solution in original post

4 REPLIES 4
Anthony_E
Community Manager
Community Manager

Hello R_F,

Thank you for using the Community Forum.

I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.

 

Regards,

Anthony-Fortinet Community Team.
Debbie_FTNT
Staff
Staff

Hey R_F,

you have essentially two options to integrate 2FA with ZTNA setup:

-> you can do a SAML authentication against a FortiAuthenticator, for example, which would then prompt for the token code

-> you could do form-based authentication (basic does not support two-factor authentication)

-> you might have to enable two-factor authentication in the proxy authentication rule (via CLI)

For example:

https://docs.fortinet.com/document/fortigate/7.0.0/new-features/591056/ztna-session-based-form-authe...

https://docs.fortinet.com/document/fortigate/7.0.0/new-features/461532/ztna-proxy-access-with-saml-a...

I hope this helps :)

+++ Divide by Cucumber Error. Please Reinstall Universe and Reboot +++
R_F

Thanks @Debbie_FTNT . missed out that document.

0xkieron
New Contributor

Hi,

 

Thanks for the above info. Do you know if it's possible to use ZTNA with FortiToken to access non web resources? When we test it only works for HTTP/S.

 

Regards,

 

Kieron

Labels
Top Kudoed Authors