Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
AgnerDNS
New Contributor

Is it possible to use google authenticator for forticlient VPN SSL instead of fortitoken?

I'm new to Fortigate and I need to get MFA working for SSLVPN users from an LDAP Server. With other manufacturers, such as Sophos, I just need to enable MFA for users and have them read the QR code in their respective authentication app. With Fortigate, do I need to use Fortitoken mobile exclusively?

Another question: is it true that to use MFA with Fortigate, I need to pay for a token?

14 REPLIES 14
funkylicious

You can enable/activate for free 2FA via email, sent to users.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Email-Two-Factor-Authentication-on-FortiGa...

But if you want a mobile app indeed it's not free.

"jack of all trades, master of none"
"jack of all trades, master of none"
AgnerDNS

But I use an LDAP server for the users; how would I handle it in this case?

 

 

 

funkylicious

Import each user on the FortiGate then configure from cli for each one:

 

       set two-factor email
       set email-to {user_email_address}

"jack of all trades, master of none"
"jack of all trades, master of none"
AgnerDNS

Is there any method to import users from LDAP to a location in Fortigate, as is the case with other manufacturers?

funkylicious

"jack of all trades, master of none"
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors