FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
mforbes
Staff
Staff
Article Id 190447

Description

 

This article describes how to restrict VPN access with two-factor and LDAP authentication.

 

Scope

 

FortiGate.


Solution

 

  1. Configure FortiGate to LDAP link.
For more details on How to configure FortiGate to use an LDAP server do not forget to validate the connection status successfully with the green checkmark.
 
LDAP_User09.png
 
  1. Import user from LDAP as 'local' user.
    User and authentication -> User Definition -> Create New.

    LDAP_User02.png
    LDAP_User03.png
  2. Assign a FortiToken to the imported LDAP user, an activation code will be sent to the email address. 
     
    LDAP_User04.png

      

     
  3. Create a Local User Group.
    •  Add LDAP users that have FortiTokens assigned.
    •  The 'Remote Group' option is not needed.
     
    LDAP_User05.png
     
     
  4. Add the 'Remote Access' group to the SSL VPN setting Authentication Portal Mapping as required.
     
    LDAP_User06.png

     
  5. Configure Firewall Policy for SSL VPN users.
     
    LDAP_User07.png