Hello,
Is it possible to setup a email 2FA for LDAP users to protect the VPN IPSec-overs-TCP connection ?
The feature is working fine in the SSL VPN as previously.
I found this KB but meaning working with a Certificat authentication :
My IPSec-over-TCP is working with a pre-shared key.
Thanks
Yes it is possible.
You need to import the ldap user on the fortigate to assign 2fa
Hello @sjoshi
Already done but not working with the IPsec VPN instead of SSLVPN
Here is the information find in the ike log :
> ike V=root:0:IPsec-TCP: EAP succeeded for user "xxx" group "XXX" 2FA=no
But in the user CLI setting :
> config user local
edit "xxx"
set type ldap
set two-factor email
set email-to "xxx"
set ldap-server "COMMUN-AD"
next
end
Any information ?
can you show me the group config.
config user group
edit XXX
show
Hi,
config user group
edit "GROUP"
set group-type firewall
set authtimeout 0
set auth-concurrent-override disable
set http-digest-realm ''
set member "XXX"
next
end
User | Count |
---|---|
2568 | |
1362 | |
796 | |
650 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.