Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Nea
New Contributor

VPN IPSec IKEv2 with ldap authentication + FortiToken : possible with the free VPN-only Client ?

Hello,

Seems we are forced to move from SSL to IPSEC VPN so we are actually trying it on our FTG901G v7.4.9

Our authentication is direct from the fortigate to Active Directory (ldaps)

It is working since we activated EAP-TTLS thank's to this trick : https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-enable-EAP-TTLS-for-IPSec-IKEv2-tun...

 

BUT, it is not working when we add a FortiToken on the account

 

I saw on this page that 2FA is supported from client v7.4.4 with IKEv2 ldap users : https://community.fortinet.com/t5/FortiGate/Technical-Tip-Overview-of-compatible-IKE-versions-user/t...

The little stars lead us to this Technical Tip and this Special Notice which explain that there is no free version of the 7.4.4 Forticlient, BUT the 7.4.3 free VPN-only agent is supposed to do the same job :

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Multi-Factor-Authentication-support-for-Wi...

https://docs.fortinet.com/document/forticlient/7.4.4/windows-release-notes/683433/special-notices

 

I've read a lot of kb, tips and fortidocs but I'm still not sure to understand : are our FortiToken supposed to work in our situation ? :

VPN IPSec IKEv2 + ldaps auth (eap-ttls) + free VPN-only agent

28 REPLIES 28
Nea
New Contributor

This fix allows an LDAP user to connect via IKEv2.

However, it doesn't work if you want to use a FortiToken with client 7.4.3.

southwes12
New Contributor

I think, i ran into the issue when i had the setting in phase1 with local id blank. I put in value Remote and also put in value on router side with Remote. Also phase 1 encryption set with only AES256-SHA256 and DH20 or DH21

southwes12

Also do not have these issues on the paid one.

southwes12

It may be the MFA was broken in 7.4.3.

Nea
New Contributor

I just edited the title of this post to add "with the free client"

 

We are still trying to know if there will be a new version of the VPN-only free client which will work with for IKEv2 vpn WITH our FortiTokens

 

The question is perhaps simply whether Fortinet will continue to maintain the VPN-only free client 

 

There is already at least one vulnerability that affects all versions of FortiOS 7.4.X : https://www.cve.org/CVERecord?id=CVE-2025-31514

That's why we would like to update to a mature 7.6 version

However, we have no solution for our VPN users on version 7.6, nor any visibility on a future solution.

 

We purchased over 200 Fortitokens in 2025 and we would like to know if we will be able to continue using them in future with the VPN-only free client.

kwcheng__FTNT

Hi

It is already stated that Forticlient 7.4.3 will not able to use Fortitoken on the KB which you had shared:

 

Using a FortiToken with EAP-TTLS is supported starting in v7.4.4. The free 7.4.3 FortiClient will be unable to connect if tokens are enabledTechnical Tip: Multi-Factor Authentication support for Windows FortiClient with LDAP (EAP-TTLS).

 

Do you need to configure a static route when passing an apple from left hand to right hand?
Nea

Okay, but can we expect a new version of the free FortiClient that will allow this?
Or will it never happen?

kwcheng__FTNT

No plan for Forticlient 7.4.4 free vpn only for now as there are no official announcement on this. You might want to find another alternative solution.

Do you need to configure a static route when passing an apple from left hand to right hand?
southwes12
New Contributor

7.4.9 OS requires some command line. 7.6.5 OS does not require command line. Forticlient ems 7.4.4 Works with 2fa, LDAP, & Fortitoken on router. 7.4.2 Free client does everything but requires IKEv1. You can use 7.4.3 free client but you will need to put the MFA code for fortitoken at the end of your password. Keep in mind you will need to do it fast before timeout on the fortitoken app.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors