Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
FortiNet_Newb
Contributor II

FortiToken Mobile Push with IPsec VPN

Has anyone successfully setup FortiToken Mobile Push authentication with an IPsec VPN.  It works fine with a SSL VPN connection, but when using an IPsec VPN connection, you receive the push request, but Approving/Denying the request from the FortiToken app does nothing.  You are still able to login by providing the token manually (if you enter it BEFORE choosing Accept/Deny), but this behavior is confusing and a pain for our users.  Is it simply not supported by FortiNet yet?  It worked without issue with our older Cisco/DUO setup.  We are on the latest FortiClient 7.06 (doesn't work with previous versions either) and connecting to a FortiGate running FortiOS 7.06.  I see in the release notes for the newest FortiOS vs 7.2 that having ftm-push enabled does not allow IPsec VPNs to connect at all, so I don't want to update to 7.2 at this point.

 

Thanks!

10 REPLIES 10
lriese01
Visitor

I had the same problem with ike1; ftm-push never worked, you had to enter the token manually. I have now switched to ike2 and it works:

- FG120xxxxxxxxxxx

- FW: v7.6.5 build3651

- Forticlient FREE: 7.4.3.6667

- Activate FTM + push on WAN1 incl. CLI: enable (see cli docu)

- Assign token to user (see documentation)

- install & Initialise on iPhone token app (see documentation)

ID 1 -8 was missing and not set correctly: important ID 2= localid = IP address from WAN1

- ID 9 and 10 are only necessary if you want to run multiple IPsec VPNs on WAN1 with different user groups or preshared keys (psksecret!

ike2-vpn-setting.jpg

 

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors