Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
smithas
New Contributor

IPSEC Remote Connection FTM-Push Support

Does the latest FortiOS (v7.4.4) support FTM-Push for IPSEC authentication? I see a number of posts in this community on this topic that indicate this is not supported with older revisions of the FortiOS.  If this is a supported method to authenticate an IPSEC remote connection, I have an issue where the IPSEC connection process does not wait for the FTM-Push to be either received or approved.  As such a connection can not be established with this enabled.

2 REPLIES 2
akumar02
Staff
Staff

Hello @smithas,

 

The IPSec VPN should be able to connect if FTM-PUSH is configured and the following BUG is fixed in 7.4.4.

 

564920 IPsec VPN fails to connect if ftm-push is configured.

 

Ref(Page: 48): https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/bf54b01b-12e2-11ef-8c42-fa163e...

 

 

Best Regards,
. . . . . . . . . . . . . . . . . . . . . . . .
Arun Kumar | TAC Engineer II
FORTINET TAC - America EAST
NSE Certified: 1,2,3,4,5,7
Office Hours: 9AM-6PM EST (Tue-Sat)
Contact: https://fortinet.com/support-and-training/support/contact.html
Community Forum: https://community.fortinet.com
# Is there anything Fortinet could have assisted with further, better, or differently?
# Simply request a Manager follow-up
smithas
New Contributor

Yes, from the release note it appears that specific issue was fixed. In this case with the FTM-Push enabled, the IPSEC authorization sequence does not pause/wait for the token request to be pushed to the user. Due to this the VPN tunnel is dropped rather quickly, and then the pushed token request will popup on the device (too late). I have looked and can not find any configurable parameters that define a wait time for the authorization sequence for the token push approval. Maybe this is still a problem with the latest FortiOS.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors