Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
damianhlozano
Contributor

Active Directory users on IPsec VPNs with 2FA

Hello team!

 

Is there a way to create VPN ipsec which could use domain users (AD) and use 2FA for each user?

In this case, is there a way to use 2FA through email?

I think, to configure a different 2FA for each user, these users should be in Fortigate, but I ask just in case that there is anything else that I cant see.

If not, do you know any other VPN which would allow this? 

Is this possible with ZTNA? (I am still very noob with ZTNA), in this case I will need to learn more

 

Thanks in advance.

Regards,

Damián

 

Damián Lozano
Damián Lozano
2 REPLIES 2
AnthonyH
Staff
Staff

Hello damianhlozano,

I do not believe I done this, but you can try:
1) Creating the IPsec Dialup VPN.
2) Configure the FortiGate and connect it to your LDAP server. https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-configure-FortiGate-to-use-an-LDAP-...
3) Configure the user for 2FA in CLI: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Email-Two-Factor-Authentication-on-FortiGa...

 

Technical Support Engineer,
Anthony.
vbandha
Staff
Staff

Hi @damianhlozano ,

 

Regarding your query "I think, to configure a different 2FA for each user, these users should be in Fortigate, but I ask just in case that there is anything else that I cant see."

 

Well they are not strictly in fortigate. What I mean is you don't need to create local user, you can create a ldap user. You are still creating individual user but the authentication happens with ldap:

Here is an article related to that:

https://community.fortinet.com/t5/FortiGate/Technical-Note-Configuring-Remote-LDAP-users-with-Two-Fa...

 

You can create the ldap user and then follow same steps to configure 2fa with email like local user:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Email-Two-Factor-Authentication-on-FortiGa...

 

Regards,

Varun

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors