Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Chua_Augustine
New Contributor II

Forticlient SSL VPN get connected without email token but no access to the network

Greetings, 

I have a weird scenario using Forticlient connecting to SSLVPN. Our users connect to our Internal network using SSLVPN when they are working remotely. They are using Forticlient VPN with email token for enhanced authentication.

Lately, we encountered issue such that user were not prompted for email token and get direct access to the network but no access to any of the servers or internal network such as file share. We have 2 Active Directory servers and that the email token is set to point to AD1 while AD2 is our primary Active Directory. Both AD are replicated.

Has anybody encounter such issue before?

6 REPLIES 6
INT1
New Contributor II

Hello, if you haven't set in fortigate  to ask for sign in on every next login i think it would save the credentials and allow them to connect without using their email and password

Chua_Augustine
New Contributor II

Thanks for the reply, INT1. I would agree with you if I have not set to ask for sign in on every next login, the system will save the credentials and allow them to connect without any needs to enter login ID and password., but the thing is that they are prompted for credential. It is just after they complete entering the credential and hit the submit button, that it went direct without prompting for email token (which should not be the case).  They should be prompted for email token, and only then allow the access. The workaround currently is to disconnect again and reconnect back, the second time reconnect, they will be prompted for email token.  Hope this clarifies.

AEK
SuperUser
SuperUser

Hi Augustine

- Which FOS version?

- Which FortiClient version?

AEK
AEK
Chua_Augustine
New Contributor II

We are running on 7.2.10 build1706(Mature) and for Forticlient 7.4.0.1658.

 

rbraha
Staff
Staff

Hi @Chua_Augustine 

Make sure that you have enabled as Two-factor Authentication - Email Based two-factor authentication, also make sure that you don't have  same local users in FGT ,because FGT first it will check his local database ,then will check LDAP or Radius server whichever replies first to his requests.

Some debug commands that you can run on FGT CLI:

 

diag debug application fnbamd -1

diag debug application sslvpn -1

diag debug enable

AEK
SuperUser
SuperUser

In addition to Braha's advice, in case you configured multiple authentication servers then follow the recommendation here:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-A-quick-guide-to-FortiGate-SSL-VPN-authent...

 

AEK
AEK
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors