Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rohit0643
New Contributor

Not getting the token

The IPsec VPN (remote access) is configured, and we are using Cloud Authenticator as the RADIUS server with 2FA enabled. IKE -1 we are using and as per (Peter TAC engineer ) the EMS does not support IKE-1 in 7.4.4 version. I'm not receiving the token and TAC also unable to provide the solution yet, It has been pending from last 14 days. 

 

Regards,

Rohit

4 REPLIES 4
saneeshpv_FTNT

Hi @rohit0643,

 

As per below article, "FortiClient 7.4.4 and later versions do not support IPsec VPN IKEv1. Configure IPsec VPN IKEv2 if using FortiClient 7.4.4 and later versions."

https://docs.fortinet.com/document/forticlient/7.4.5/ems-administration-guide/343169/troubleshooting... 

 

Please use Ikev2 instead of Ikev1 for your Implementation.

 

Best Regards,
Saneesh

rohit0643

I have already seen this article, and the settings are already configured in IKE-2. However, the problem is that the token for 2FA login is not being coming to the user's mobile phone.

Markus_M

more detail will be needed. It sounds like the notification doesn't arrive at the end users phone. On the FortiAuthenticator https://fac-ip/debug, enable the RADIUS debug and reproduce the issue. There will be something about a "session_id" when the push is generated.
Other very quick idea is to crosscheck against memory requirements of FortiAuthenticator and reboot when possible and see whether the issue disappears.

- Markus
filiaks1
Contributor III

What about radius debug ?

 

RADIUS authentication troubleshooting - Fortinet Community

 

This is for Microsoft but the same stuff:

 

Radius authentication with Azure Multifa... - Fortinet Community

 

Also I have not used FortiAuthenticator Cloud but the user tab should show if a token was assigned to the user.

 

Also this could be useful FortiIdentity Cloud's basic troublesh... - Fortinet Community but it is when you are using the forticloud just for MFA and radius is locally send to a local radius server, so keep that in mind.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors