Hi all, my first post here. Perhaps someone can help.
Our firewall is configured to connect to an on-prem Radius server (NPS). Hybrid connectivity is setup so users are also in Microsoft Entra with MFA setup.
Firewall is configured to point to Radius and only allow vpn connections if users are part of a group.
For some reason, any new users that we setup do NOT get the MFA prompt in Forticlient (using either EMS client or standard) , However, old users' , setup over 6 months ago, work just fine!
I did find this article and will try to determine if it's applicable:
However, what baffles me is that old users are OK, but, new users are not. We've tried from the same workstation. The MFA prompt (that extra field in forticlient that asks for the token does not show) and it errors out at 45%.
Has anybody encountered this before?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Based on your description I think that the changes need to be done in the RADIUS server. The token is asked as an addition RADIUS challenge to FGT that triggers the new prompt in FCT. It looks like this is not being asked by the NPS for the new users. You can also check the debugs in FGT, refer to this article for SSL VPN troubleshooting tips.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1660 | |
1071 | |
751 | |
443 | |
219 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.