Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ArielZusya
New Contributor

Passing domain-joined Windows 10 Pro user credentials for L2TP VPN connection

We have Microsoft AD on premises for domain control/user authentication. We have our Windows 10 users remotely connecting to our local network via a L2TP VPN with pre-shared passphrase through a FortiGate 200E running 6.4.4. We have the FortiGate configured to pull credentials for VPN-authorized users from our AD.

 

When configuring the VPN on our users' computers we create the profile in the VPN subsection of Windows Settings and then edit the properties of that VPN in Network Connections changing the Security tab so "Allow these protocols" is selected and PAP and CHAP are checked but MS-CHAP v2 is not. As a result, every time users connect they are prompted for their AD logon name and current password (the same logon name and password they use to log into Windows).

 

I'd love to enable the VPN profile to either use EAP and automatically pass windows logon name and password or MS-CHAP v2 and automatically pass Windows logon name and password (or some other method I'm not yet aware of that does the same thing). Can this be done with an L2TP VPN on a FortiGate? If so, how do I enable this functionality? Thanks in advance!

0 REPLIES 0
Labels
Top Kudoed Authors