Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ScottyT
Visitor

Forticlient EMS IPSEC VPN w/MFA

We are rolling out the IPSEC VPN delivered to Windows laptops using the EMS client. Right now, we have the LDAP authentication for the IPSEC VPN integrated with Duo MFA. Users receive a Duo push to their mobile phones at every VPN login or reconnect. 

 

Does anyone have a better MFA approach that would allow the device/user to be "trusted" for a period of time, so they don't get repetitive MFA prompts at every VPN login? I know there are lots of SSO/Integration options with the SSL VPN, but that appears to be going away, thanks to all the security issues. I can't find one that will integrate via LDAP/Radius with the IPSEC VPN. Thanks!

0 REPLIES 0
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors