Hello,
We are moving pretty much everything to Fortinet (sick & tired of being stuck between vendors pointing fingers at each other).
In the process of deploying Fortiauthenticator for MFA on VPN and Desktops, but before I register IP address for already installed and configured FA, I'd like to know if it should be in DMZ?
-Everything is on-prem.
-To start with, we'll b using OTP for MFA
-Windows Environment (Win10/2016)
-Local CA root installed and I can import users from AD.
Is there anything else I should watch for?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello,
You don't need public IP for FAC. FAC can be behind the firewall, in this case FortiGate as you are moving everything already.
FortiGate can hold that public IP and FAC can stay behind the NAT. You will probably need NAT for example if you want to use FortiToken mobile push notification, because in this case phone will directly contact (FortiGate as FAC is behind the NAT in this case) FAC.
Here is the KB that explains that:
Make sure that FAC has internet connection also, as it will need that for token assignment for example.
Other then that you want to make sure that FAC will have connection to the internal network, because it will need to contact the LDAP server in this case.
Also connection between the FortiGate that holds SSL VPN for example and acts as radius client.
FAC also needs to have one IP that will be tied to the license file itself (that IP address can be from private range). You can use the same IP for GUI, authentication, license, but in this case if you change IP for authentication (radius, tacacs, etc..) in the future license will not be valid and you will have to add new IP to the support portal and then redownload and upload license again to the FAC.
If you have more question, be free to ask them :)
Best regards,
Lazar Marinovic
A note to the above:
The licence and IP address issue Lazar mentioned above applies to FortiAuthenticator VMs only, not hardware devices :)
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1688 | |
1087 | |
752 | |
446 | |
227 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.