Hi,
We have recently understood that IKEV1 is being phased out and we are currently studying IKEV2 for our IPSEC Dialup connections.
We are a Windows house so we will be using LDAP for our users and I would like to know if anyone can provide feedback about which MFA or 2FA they are using and any associated problems.
I have seen varying information that stated that if we use EAP-MSCHAPV2 we cannot use FortiToken with LDAP accounts. And if we use EAP-TTLS we must have EMS licences but Fortitokens might still be possible.
Can someone confirm which setup the have successfully setup, it must be a LDAP setup and which MFA they are using and any roadblocks that they have come across.
Cheers
hi,
you can enable EAP-TTLS even tho you dont have EMS license, https://community.fortinet.com/t5/FortiGate/Technical-Tip-IKEv2-tunnel-fails-when-LDAP-based-usergro...
you can either use RADIUS/NPS w/ IKEv2 and FortiToken, https://community.fortinet.com/t5/FortiGate/Technical-Tip-IKEv2-Dialup-IPsec-tunnel-with-RADIUS-and/...
or you can try IKEv2 w/ SAML and a IdP like Okta, DUO, FortiAuth or even Keycloak
Hi RW2,
FortiClient added support for EAP-TTLS & LDAP in IPSec VPN starting in version 7.4.3.
You can configure it using the <eap_method> option in the XML configuration ,
However, as per one of the known issues 1031789 , Windows FCT 7.4.3 does not support IPsec IKEv2 EAP-TTLS 2FA, but should be supported in 7.4.4 and FGT 7.4.9.
Best regards,
| User | Count |
|---|---|
| 2806 | |
| 1425 | |
| 812 | |
| 757 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.