Im willing to bet you are using LDAP groups on the FG for users that you
want to enable 2FA for? When you use an LDAP group (Remote group created
on the FG), the user authentication request first checks for a local
user. If not found, the FG then for...