Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
TopJimmy
New Contributor

Admin login with 2-factor

Version 4.3.x has 2 factor for admin login that seems to support SMS without using FortiTokens so my questions is, how do you configure it? Ive done the following but I' m at a loss at to what they are looking for in the SMS Provider section for " mail-server" . Any suggestions for getting this working with Verizon Wireless would be helpful. config user sms-provider edit <provider_name> set mail-server <server_email> next end Maybe I am wrong at thinking it doesn' t need a FortiToken? Here is the section of the handbook:
SMS SMS two-factor authentication sends the token code in an SMS text message to the mobile device indicated when this user attempts to logon. This token code is valid for 60 seconds. If you enter this code after that time, it will not be accepted. Enter this code when prompted at logon to be authenticated. SMS two-factor authentication has the benefit that you do not require email service before logging on. A potential issue is if the mobile service provider does not send the SMS text message before the 60 second life of the token expires. Before configuring SMS, you must configure the email server for sending email from the FortiGate unit and one or more SMS providers in the CLI. To configure the SMTP email address for your FortiGate unit - web-based manager 1 Go to the email server under Log&Report->Log Config->Alert e-mail. 2 Enter the SMTP Server and Email from address. 3 If applicable, enable Authentication on the SMTP server and enter the SMTP username and password to use. 4 Select Apply. To configure an SMS provider - CLI config user sms-provider edit <provider_name> set mail-server <server_email> next end To configure SMS two-factor authentication - web-based manager 1 To modify an: • administrator account, go to System > Admin > Administrators, or • user account go to User > User. 2 Select an existing account or select Create New. 3 Select Enable Two-factor Authentication. 4 Select SMS. 5 Choose the SMS provider from the drop down list. 6 Enter the phone number of the mobile device that will receive the SMS text messages. If you have problems receiving the token codes via SMS messaging, contact your mobile provider to ensure you are using the correct phone number format to receive text messages and that your current mobile plan allows text messages.
-TJ
-TJ
5 REPLIES 5
Carl_Wallmark
Valued Contributor

Hi, You are correct, there are 3 ways of getting 2-factor. 1. FortiToken 2. SMS 3. Email To configure SMS, you simply add a SMS-gateway server (email server). This has to done in CLI. After that you can add phonenumbers in the GUI, what happens is that the Fortigate will send an email to the SMS gateway server and then passing it as a SMS. For example: Lets say you add " smsgateway.com" as SMS email server. You add a phonenumber 123456. The Fortigate will send something like " 123456@smsgateway.com" to that email server. This solution requires that you have some sort of subscription on a SMS service, if your mobilevendor dont have one for free. (some do).

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
veechee
New Contributor

Can anyone recommend a SMS gateway provider to cover common North American providers?
TopJimmy

ORIGINAL: veechee Can anyone recommend a SMS gateway provider to cover common North American providers?
+1
-TJ
-TJ
soma043
New Contributor

I created an SMS provider for Verizon (almost all of our employees are Verizon). conf user sms-provider edit Verizon set mail-server vtext.com next end Now, when I create a user, I choose " Enable Two-factor Authentication" and then SMS. Since this user has a Verizon phone, I choose Verizon in the drop down and then put their phone number. This generates an email to xxxxxxxx@vtext.com which is the email method of sending SMS on Verizon' s system. I suspect something similar could be done for the other carriers.
rwpatterson
Valued Contributor III

A list of SMS gateways I collected from the Internet over time: ##################################################### # SMS provider domain name list. # Note: The phone numbers are 10 digits without punctuation # ------------------ ---------------------------------------------------------- [ul]
  • AirTouch Cellular phonenumber@airtouchpaging.com
  • Alltel: phonenumber@message.alltel.com
  • Ameritech Cellular phonenumber@paging.acswireless.com
  • AT&T: phonenumber@txt.att.net
  • AT&T MMS: phonenumber@MMS.att.net
  • Bell Atlantic phonenumber@message.bam.com
  • BellSouth phonenumber@wireless.bellsouth.com
  • Boost Mobile phonenumber@myboostmobile.com
  • Cingular: phonenumber@cingularme.com
  • Comcast Cellular phonenumber@cellularone.tstmsg.com
  • GTE Wireless phonenumber@messagealert.com
  • Metro PCS: phonenumber@MyMetroPcs.com
  • Nextel: phonenumber@messaging.nextel.com
  • Omnipoint phonenumber@omnipointpcs.com
  • Pacific/Nevada Bell 1+phonenumber@pacbellpcs.com
  • Powertel: phonenumber@ptel.net
  • PrimeCo phonenumber@primeco.textmessage.com
  • Southwestern Bell phonenumber@email.swbw.com
  • Sprint: phonenumber@messaging.sprintpcs.com
  • SunCom: phonenumber@tms.suncom.com
  • T-Mobile: phonenumber@tmomail.net
  • Telecorp phonenumber@mobile.att.net
  • Tritel phonenumber@mobile.att.net
  • Triton PCS phonenumber@mobile.att.net
  • U.S. West phonenumber@uswestdatamail.com
  • US Cellular: phonenumber@email.uscc.net
  • Verizon: phonenumber@vtext.com
  • Virgin Mobile: phonenumber@vmobl.com
  • Voicestream phonenumber@voicestream.net [/ul]
  • Bob - self proclaimed posting junkie!
    See my Fortigate related scripts at: http://fortigate.camerabob.com

    Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
    Announcements

    Select Forum Responses to become Knowledge Articles!

    Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

    Labels
    Top Kudoed Authors