Hello,
Seems we are forced to move from SSL to IPSEC VPN so we are actually trying it on our FTG901G v7.4.9
Our authentication is direct from the fortigate to Active Directory (ldaps)
It is working since we activated EAP-TTLS thank's to this trick : https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-enable-EAP-TTLS-for-IPSec-IKEv2-tun...
BUT, it is not working when we add a FortiToken on the account
I saw on this page that 2FA is supported from client v7.4.4 with IKEv2 ldap users : https://community.fortinet.com/t5/FortiGate/Technical-Tip-Overview-of-compatible-IKE-versions-user/t...
The little stars lead us to this Technical Tip and this Special Notice which explain that there is no free version of the 7.4.4 Forticlient, BUT the 7.4.3 free VPN-only agent is supposed to do the same job :
https://docs.fortinet.com/document/forticlient/7.4.4/windows-release-notes/683433/special-notices
I've read a lot of kb, tips and fortidocs but I'm still not sure to understand : are our FortiToken supposed to work in our situation ? :
VPN IPSec IKEv2 + ldaps auth (eap-ttls) + free VPN-only agent
Hi, from the KB documents, it clearly mentions that for IKE v2 LDAP with MFA requires the FortiClient 7.4.4. As you are using FCT 7.4.3, it might not work.
So, can you tell us if a new version of the VPN-only free FortiClient is coming soon?
Because currently, we are stuck on FortiOS version 7.4.9 since the SSL VPN disappears in 7.6 and the IPsec VPN does not work with our FortiTokens.
Is does work. I have it working with 7.6.5 OS. Forticlient 7.4.4
Under IKE change Accepted peer ID to Specific peer ID. Put Remote in the space below. You will need to add it in you Forticlient side as well.
Also make sure Encryption - authentication only has AES128 - SHA256 and AES256 - SHA256 only list on firewall side only.
Thanks for sharing.
We haven't planned to purchase licenses for FortiClients.
That's why I'm trying to find out if the free FortiClient is planned to work with IPSec IKEv2, LDAP users, and FortiTokens
any reason why you are not considering IKEv1 ?
i dont think that there will be any free versions in the future.
SSLVPN and IKE1 are being removed due to security issues on the forticlient side is what I was told.
Created on 12-30-2025 09:37 AM Edited on 12-30-2025 09:38 AM
IKEv1 is removed in FortiClient 7.4.4 which is a paid service/feature/application(EMS).
if he doesnt have a EMS license, he has no need to worry about that and if he buys one, he solves his IKEv2 issue.
Created on 12-30-2025 01:29 PM Edited on 12-30-2025 01:30 PM
IKEv1 is not an option, and I am indeed trying to find out if the Forticlient is becoming a mandatory paid service.
Yes, it works with IKEv1, but we're not considering it because I think it's obsolete.
https://www.ietf.org/archive/id/draft-ietf-ipsecme-ikev1-algo-to-historic-07.html
The answer is yes. I am using it currently. The only thing that does not work is password changes on vpn logon. You would need to have your user change their password at least one day before, otherwise they cannot login.
Fix for Free Forticlient How to enable EAP-TTLS for IPSec IKEv2 tu... - Fortinet Community
| User | Count |
|---|---|
| 2895 | |
| 1448 | |
| 848 | |
| 825 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.