I have successfully configured FTM push. It works great. I have two questions:
1. Is a push considered less secure than a user need to manually input the 6 digit number?
2. I have a custom SSL cert loaded for VPN and administration. Although FTM push works with the default facotry cert is it more/less secure to use the certificate i uploaded for VPN and admin?
TIA
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Good Morning @casteld73,
Regarding your questions:
FTM Push and enter the code manually both are secure
Here is the process of authentication via Mobile Token:
FortiGate sends a DNS query to the FortiToken Mobile Push proxy server (push.fortinet.com).
FortiGate connects to the proxy server via an encrypted connection over TCP/443.
The proxy server handles the notification request by making a TLS connection with either Apple (for iOS) or Google (for Android) notification servers. Notification data may include the recipient, session, FortiGate callback IP and port, and so on.
The notification service from either Apple or Google notifies the user's mobile device of the push request.
The FortiToken Mobile application on the user's mobile displays a prompt for the user to either Approve or Deny the request.
You can also find an article: https://docs.fortinet.com/document/fortigate/7.4.1/administration-guide/927108/fortitoken-mobile-pus...
Regarding the certificate, per knowledge, it won't be a matter if it uses the Factory cert. However, I do not have a concrete answer but will try to get it for you and update the thread.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1731 | |
1098 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.