Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
AndrArt
New Contributor

IPSec VPN with Azure/Entra mfa

Hi,

 

I am trying to set up a mode config IPSec tunnel with Entra MFA

 

So far I have set up the VPN tunnel, on prem NPS server, And Radius client on a fortigate.

VPN users are supposed to be authenticated by AD group membership.

The VPN tunnel is successfully established if using local NPS permissions set and the users are able to reach the resources they are supposed to.

I have installed the MFA NPS extension on the server, and now I am getting "The request was discarded by a third-party extension DLL file.". As long as I understand I need some more configuration on the Entra side to do.

After digging in documentation, the main question that has arisen for me is - is such configuration possible to implement at all? Has anyone done it? Or should I go to SSL-VPN MFA?

 

3 REPLIES 3
sw2090
SuperUser
SuperUser

hm we are doing IPSec VPN with AD users and FortiToken as 2FA. However we happen to run a FortiAuthenticator that acts as radius server for the FGT. Then FAC does all the authentication here and FGt just has the FAC as radius server and the vpn set to use a radius user group for xauth. The radius groups are on FAC and maintained there and it even automatically polls the ad users from our DCs based on AD group. 

I haven't however ever tried with only a FGT (and DCs). At least not with 2FA.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
AndrArt
New Contributor

Thank you for your response, FGT-DCs NPAS combination works, but I cannot get them to do the azure/entra 2FA. FortiAuthenticator, is not an option for me, since the client is not willing to pay for the tokens, let alone the Authenticator. So it seems I will have to go back to the drawing board and do SSL-VPN with azure 2FA instead of IPSec.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors