Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Mirgani
New Contributor

IPsec 2FA issue when using email as asecond factor

 i have IPsec Dialup VPN, my remote connector couldn't validate when 2FA via email is arrived the only users that can verify with 2fa is less than 50 sec.

i have changed the validity of email time to 3 mints, but nothing change.

 

i went through similar issue but fortigate they confirmed that it's has been solved in 7.6.3 i have upgraded the fortios issue still exist.

1 REPLY 1
AEK
SuperUser
SuperUser

config system global
set two-factor-email-expiry 300
set remoteauthtimeout 300
end

 

'remoteauthtimeout' command will override the two-factor-email-expiry, so increase both timers. The mentioned value is in seconds.
...
This timer is not correctly applied in some of the latest versions (v7.2.10+, v7.4.5+, v7.6.1+) when using IPsec (IKEv2) Remote Access VPN. This is a known issue, tracked under bug 1087651, which will be fixed in v7.6.3 and v7.4.8 (until now).
If upgrading to v7.6.3 and v7.4.8 does not resolve the issue, use IKEv1 as a workaround.

 

Ref:  https://community.fortinet.com/t5/FortiGate/Technical-Tip-Increasing-email-Token-expiry-time/ta-p/19...

 

Hope it helps.

AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors