Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
RW2
New Contributor II

IKEV2 + LDAP + MFA

Hi, 

We have recently understood that IKEV1 is being phased out and we are currently studying IKEV2 for our IPSEC Dialup connections.

We are a Windows house so we will be using LDAP for our users and I would like to know if anyone can provide feedback about which MFA or 2FA they are using and any associated problems.

I have seen varying information that stated that if we use EAP-MSCHAPV2 we cannot use FortiToken with LDAP accounts.  And if we use EAP-TTLS we must have EMS licences but Fortitokens might still be possible.

Can someone confirm which setup the have successfully setup, it must be a LDAP setup and which MFA they are using and any roadblocks that they have come across.

Cheers 

2 REPLIES 2
funkylicious
SuperUser
SuperUser

hi,

you can enable EAP-TTLS even tho you dont have EMS license, https://community.fortinet.com/t5/FortiGate/Technical-Tip-IKEv2-tunnel-fails-when-LDAP-based-usergro... 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-enable-EAP-TTLS-for-IPSec-IKEv2-tun... 

 

you can either use RADIUS/NPS w/ IKEv2 and FortiToken, https://community.fortinet.com/t5/FortiGate/Technical-Tip-IKEv2-Dialup-IPsec-tunnel-with-RADIUS-and/... 

or you can try IKEv2 w/ SAML and a IdP like Okta, DUO, FortiAuth or even Keycloak 

"jack of all trades, master of none"
"jack of all trades, master of none"
tbarua
Staff
Staff

Hi RW2,

FortiClient added support for EAP-TTLS & LDAP in IPSec VPN starting in version 7.4.3. 

You can configure it using the <eap_method> option in the XML configuration , 

https://docs.fortinet.com/document/forticlient/7.4.0/new-features/907253/eap-ttls-support-for-ipsec-...

However, as per one of the known issues 1031789 ,  Windows FCT 7.4.3 does not support IPsec IKEv2 EAP-TTLS 2FA, but should be supported in 7.4.4 and FGT 7.4.9. 

 

Best regards,

Tuli
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors