CyberInsurance is requiring MFA on all remote connections.
We are currently using IPSec VPN for all remote connections.
Aside from Fortitoken, what other MFA options might I have have with IPSec VPN connections? Ideally I would to configure SAML to EntraID and let that handle the MFA, but all the documentation and posts I find are related to configuring that for SSL VPN... which we are not and do not want to use.
Is SAML an option for IPSec VPN and if so, is there a straight-forward guide for configuring it?
Hi @sunio,
SAML authentication for dialup VPN is not supported at this time. It is still under development. You can consider using certificate authentication: https://docs.fortinet.com/document/fortigate/7.4.1/administration-guide/443323/dialup-ipsec-vpn-with...
Regards,
This might help. Let me know how this goes IPsec VPN SAML-based authentication | FortiClient 7.2.4 | Fortinet Document Library
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1749 | |
1114 | |
765 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.