Hello,
Seems we are forced to move from SSL to IPSEC VPN so we are actually trying it on our FTG901G v7.4.9
Our authentication is direct from the fortigate to Active Directory (ldaps)
It is working since we activated EAP-TTLS thank's to this trick : https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-enable-EAP-TTLS-for-IPSec-IKEv2-tun...
BUT, it is not working when we add a FortiToken on the account
I saw on this page that 2FA is supported from client v7.4.4 with IKEv2 ldap users : https://community.fortinet.com/t5/FortiGate/Technical-Tip-Overview-of-compatible-IKE-versions-user/t...
The little stars lead us to this Technical Tip and this Special Notice which explain that there is no free version of the 7.4.4 Forticlient, BUT the 7.4.3 free VPN-only agent is supposed to do the same job :
https://docs.fortinet.com/document/forticlient/7.4.4/windows-release-notes/683433/special-notices
I've read a lot of kb, tips and fortidocs but I'm still not sure to understand : are our FortiToken supposed to work in our situation ? :
VPN IPSec IKEv2 + ldaps auth (eap-ttls) + free VPN-only agent
Hello forti13,
Thanks for sharing.
We've reached the same conclusion.
Now we'd like Fortinet to tell us if they plan to release a new VPN-only client that will allow this configuration. We lack visibility and are stuck on FortiOS 7.4 because of this.
No plan for now. You can raise this request to your local Fortinet Sales team.
That's what I did; I had a call with our Fortinet account managers last night.
They also don't know if there will be any new versions of the free VPN-only FortiClient.
They told me that a new license has just appeared in the catalog:
Standalone FortiClient VPN Bundle including Firmware & General Updates, Enhanced Support (email/chat) and VPN. Subscription for up to 3 endpoints.
The license is slightly cheaper than the EMS subscription.
This leads me to believe that the free client is going to disappear.
What's unfortunate is that Fortinet isn't being clear with us. The communication is poor, or nonexistent.
Highly understood your concern.
The current version of free client should still remain but you might want to avoid expecting a new version for free client for now.
Have you tried setting up the fortitoken push on router to see if that works? Also try adding the 2fa token to the end of the user's password. Make sure to get it in before it expires.
Have you tried setting up the fortitoken push on router to see if that works? Also try adding the 2fa token to the end of the user's password. Make sure to get it in before it expires.
Encounter the same situation, we rollback to 7.2.12 and run ikev1 instead.
cant simply throw token away and uses new VPN solution.
probably stay on 7.2.12 till new solutions is out
| User | Count |
|---|---|
| 2914 | |
| 1452 | |
| 852 | |
| 826 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.