We have Microsoft AD on premises for domain control/user authentication. We have our Windows 10 users remotely connecting to our local network via a L2TP VPN with pre-shared passphrase through a FortiGate 200E running 6.4.4. We have the FortiGate configured to pull credentials for VPN-authorized users from our AD.
When configuring the VPN on our users' computers we create the profile in the VPN subsection of Windows Settings and then edit the properties of that VPN in Network Connections changing the Security tab so "Allow these protocols" is selected and PAP and CHAP are checked but MS-CHAP v2 is not. As a result, every time users connect they are prompted for their AD logon name and current password (the same logon name and password they use to log into Windows).
I'd love to enable the VPN profile to either use EAP and automatically pass windows logon name and password or MS-CHAP v2 and automatically pass Windows logon name and password (or some other method I'm not yet aware of that does the same thing). Can this be done with an L2TP VPN on a FortiGate? If so, how do I enable this functionality? Thanks in advance!
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1688 | |
1087 | |
752 | |
446 | |
226 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.