Has anyone successfully setup FortiToken Mobile Push authentication with an IPsec VPN. It works fine with a SSL VPN connection, but when using an IPsec VPN connection, you receive the push request, but Approving/Denying the request from the FortiToken app does nothing. You are still able to login by providing the token manually (if you enter it BEFORE choosing Accept/Deny), but this behavior is confusing and a pain for our users. Is it simply not supported by FortiNet yet? It worked without issue with our older Cisco/DUO setup. We are on the latest FortiClient 7.06 (doesn't work with previous versions either) and connecting to a FortiGate running FortiOS 7.06. I see in the release notes for the newest FortiOS vs 7.2 that having ftm-push enabled does not allow IPsec VPNs to connect at all, so I don't want to update to 7.2 at this point.
Thanks!
I had the same problem with ike1; ftm-push never worked, you had to enter the token manually. I have now switched to ike2 and it works:
- FG120xxxxxxxxxxx
- FW: v7.6.5 build3651
- Forticlient FREE: 7.4.3.6667
- Activate FTM + push on WAN1 incl. CLI: enable (see cli docu)
- Assign token to user (see documentation)
- install & Initialise on iPhone token app (see documentation)
ID 1 -8 was missing and not set correctly: important ID 2= localid = IP address from WAN1
- ID 9 and 10 are only necessary if you want to run multiple IPsec VPNs on WAN1 with different user groups or preshared keys (psksecret!
| User | Count |
|---|---|
| 2881 | |
| 1446 | |
| 843 | |
| 822 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.