Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
21546533
New Contributor

Dialup IPSec IKEv2 VPN Config using Duo Proxy and NPS

We are looking to migrate to an IKEv2 Dialup VPN with Duo Proxy for MFA and integrating with NPS.  Does anyone have a working config they can provide for this configuration?  I can't seem to find anything online.

1 REPLY 1
Markus_M
Staff & Editor
Staff & Editor

What protocol is the Dou Proxy proxying? LDAP or RADIUS?
If RADIUS - this should work:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-IKEv2-Dialup-IPsec-tunnel-with-RADIUS-and/... - DUO being a proxy should basically only mean that your server on FortiGate would be DUO and on DOU the target would be NPS. After authentication success against NPS, DOU would ask for a second factor. Once answered, DUO would respond to FortiGate as the RADIUS server.

- Markus
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors