Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Nea
New Contributor

VPN IPSec IKEv2 with ldap authentication + FortiToken : possible with the free VPN-only Client ?

Hello,

Seems we are forced to move from SSL to IPSEC VPN so we are actually trying it on our FTG901G v7.4.9

Our authentication is direct from the fortigate to Active Directory (ldaps)

It is working since we activated EAP-TTLS thank's to this trick : https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-enable-EAP-TTLS-for-IPSec-IKEv2-tun...

 

BUT, it is not working when we add a FortiToken on the account

 

I saw on this page that 2FA is supported from client v7.4.4 with IKEv2 ldap users : https://community.fortinet.com/t5/FortiGate/Technical-Tip-Overview-of-compatible-IKE-versions-user/t...

The little stars lead us to this Technical Tip and this Special Notice which explain that there is no free version of the 7.4.4 Forticlient, BUT the 7.4.3 free VPN-only agent is supposed to do the same job :

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Multi-Factor-Authentication-support-for-Wi...

https://docs.fortinet.com/document/forticlient/7.4.4/windows-release-notes/683433/special-notices

 

I've read a lot of kb, tips and fortidocs but I'm still not sure to understand : are our FortiToken supposed to work in our situation ? :

VPN IPSec IKEv2 + ldaps auth (eap-ttls) + free VPN-only agent

36 REPLIES 36
Nea
New Contributor

Hello forti13,

Thanks for sharing.
We've reached the same conclusion.
Now we'd like Fortinet to tell us if they plan to release a new VPN-only client that will allow this configuration. We lack visibility and are stuck on FortiOS 7.4 because of this.

kwcheng__FTNT

No plan for now. You can raise this request to your local Fortinet Sales team.

Do you need to configure a static route when passing an apple from left hand to right hand?
Nea

That's what I did; I had a call with our Fortinet account managers last night.
They also don't know if there will be any new versions of the free VPN-only FortiClient.


They told me that a new license has just appeared in the catalog:
Standalone FortiClient VPN Bundle including Firmware & General Updates, Enhanced Support (email/chat) and VPN. Subscription for up to 3 endpoints.
The license is slightly cheaper than the EMS subscription.
This leads me to believe that the free client is going to disappear.


What's unfortunate is that Fortinet isn't being clear with us. The communication is poor, or nonexistent.

kwcheng__FTNT

Highly understood your concern.

The current version of free client should still remain but you might want to avoid expecting a new version for free client for now.

Do you need to configure a static route when passing an apple from left hand to right hand?
southwes12
New Contributor

Have you tried setting up the fortitoken push on router to see if that works? Also try adding the 2fa token to the end of the user's password. Make sure to get it in before it expires.

southwes12
New Contributor

Have you tried setting up the fortitoken push on router to see if that works? Also try adding the 2fa token to the end of the user's password. Make sure to get it in before it expires.

owen911
New Contributor III

Encounter the same situation, we rollback to 7.2.12 and run ikev1 instead.
cant simply throw token away and uses new VPN solution.
probably stay on 7.2.12 till new solutions is out

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors