Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Nea
New Contributor

VPN IPSec IKEv2 with ldap authentication + FortiToken : possible with the free VPN-only Client ?

Hello,

Seems we are forced to move from SSL to IPSEC VPN so we are actually trying it on our FTG901G v7.4.9

Our authentication is direct from the fortigate to Active Directory (ldaps)

It is working since we activated EAP-TTLS thank's to this trick : https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-enable-EAP-TTLS-for-IPSec-IKEv2-tun...

 

BUT, it is not working when we add a FortiToken on the account

 

I saw on this page that 2FA is supported from client v7.4.4 with IKEv2 ldap users : https://community.fortinet.com/t5/FortiGate/Technical-Tip-Overview-of-compatible-IKE-versions-user/t...

The little stars lead us to this Technical Tip and this Special Notice which explain that there is no free version of the 7.4.4 Forticlient, BUT the 7.4.3 free VPN-only agent is supposed to do the same job :

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Multi-Factor-Authentication-support-for-Wi...

https://docs.fortinet.com/document/forticlient/7.4.4/windows-release-notes/683433/special-notices

 

I've read a lot of kb, tips and fortidocs but I'm still not sure to understand : are our FortiToken supposed to work in our situation ? :

VPN IPSec IKEv2 + ldaps auth (eap-ttls) + free VPN-only agent

28 REPLIES 28
hpenmetsa
Staff
Staff

Hi, from the KB documents, it clearly mentions that for IKE v2 LDAP with MFA requires the FortiClient 7.4.4. As you are using FCT 7.4.3, it might not work.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Multi-Factor-Authentication-support-for-Wi...

Nea
New Contributor

So, can you tell us if a new version of the VPN-only free FortiClient is coming soon?

Because currently, we are stuck on FortiOS version 7.4.9 since the SSL VPN disappears in 7.6 and the IPsec VPN does not work with our FortiTokens.

southwes12
New Contributor

Is does work. I have it working with 7.6.5 OS. Forticlient 7.4.4

 

Under IKE change Accepted peer ID to Specific peer ID. Put Remote in the space below. You will need to add it in you Forticlient side as well.

Also make sure Encryption - authentication only has AES128 - SHA256 and AES256 - SHA256 only list on firewall side only.

Nea
New Contributor

Thanks for sharing.
We haven't planned to purchase licenses for FortiClients.
That's why I'm trying to find out if the free FortiClient is planned to work with IPSec IKEv2, LDAP users, and FortiTokens

 

funkylicious

any reason why you are not considering IKEv1 ?

i dont think that there will be any free versions in the future.

"jack of all trades, master of none"
"jack of all trades, master of none"
southwes12

SSLVPN and IKE1 are being removed due to security issues on the forticlient side is what I was told. 

funkylicious

IKEv1 is removed in FortiClient 7.4.4 which is a paid service/feature/application(EMS).

if he doesnt have a EMS license, he has no need to worry about that and if he buys one, he solves his IKEv2 issue.

"jack of all trades, master of none"
"jack of all trades, master of none"
Nea

IKEv1 is not an option, and I am indeed trying to find out if the Forticlient is becoming a mandatory paid service.

Nea

Yes, it works with IKEv1, but we're not considering it because I think it's obsolete.

https://www.ietf.org/archive/id/draft-ietf-ipsecme-ikev1-algo-to-historic-07.html

southwes12
New Contributor

The answer is yes. I am using it currently. The only thing that does not work is password changes on vpn logon. You would need to have your user change their password at least one day before, otherwise they cannot login. 

Fix for Free Forticlient How to enable EAP-TTLS for IPSec IKEv2 tu... - Fortinet Community

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors