Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
New Contributor

IPSec VPN with Azure/Entra mfa



I am trying to set up a mode config IPSec tunnel with Entra MFA


So far I have set up the VPN tunnel, on prem NPS server, And Radius client on a fortigate.

VPN users are supposed to be authenticated by AD group membership.

The VPN tunnel is successfully established if using local NPS permissions set and the users are able to reach the resources they are supposed to.

I have installed the MFA NPS extension on the server, and now I am getting "The request was discarded by a third-party extension DLL file.". As long as I understand I need some more configuration on the Entra side to do.

After digging in documentation, the main question that has arisen for me is - is such configuration possible to implement at all? Has anyone done it? Or should I go to SSL-VPN MFA?



hm we are doing IPSec VPN with AD users and FortiToken as 2FA. However we happen to run a FortiAuthenticator that acts as radius server for the FGT. Then FAC does all the authentication here and FGt just has the FAC as radius server and the vpn set to use a radius user group for xauth. The radius groups are on FAC and maintained there and it even automatically polls the ad users from our DCs based on AD group. 

I haven't however ever tried with only a FGT (and DCs). At least not with 2FA.


"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
New Contributor

Thank you for your response, FGT-DCs NPAS combination works, but I cannot get them to do the azure/entra 2FA. FortiAuthenticator, is not an option for me, since the client is not willing to pay for the tokens, let alone the Authenticator. So it seems I will have to go back to the drawing board and do SSL-VPN with azure 2FA instead of IPSec.


Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Top Kudoed Authors