Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
FXE_FTNT
New Contributor II

Multiple FortiGate Integration to FortiToken

Hi Guys,

 

I have multiple FGT for my remote-access VPN (FortiClient) and I wanted to integrate it with LDAP and FortiToken for 2FA access though I don't have FortiAuthenticator.

 

Can I integrate my FGTs to my LDAP then integrate my FGTs to FortiToken Cloud? I believe for the FTK hardware/mobile, it just needs to be 1 FGT to 1 FTK. Can FTK Cloud do 2x FGT to 1x FTK for example, user1 log in to FGT1 and it is successful then user1 log out and connect to my FGT2, will user1 still be able to challenge with 2FA via FortiCloud?

 

Thanks

5 REPLIES 5
rbraha
Staff
Staff

Hi @FXE_FTNT 

 

Yes that can be possible, please check the below documentation. 

 

https://docs.fortinet.com/document/fortitoken-cloud/latest/admin-guide/625594/a-single-ftc-user-in-m...

DerekWSmall
New Contributor II

This link does explain that it's possible, but what is the best way to actually do it?  Do you have define all your users on each Fortigate, or is there a way to have second (or third, forth, etc) Fortigates just sync/pull the user definition from FTC?  Seems like managing the users on all the individual Fortigate would be troublesome to say the least.  Isn't there a way to centrally manage the users (like in FTC), and then push the users to the individual Fortigates?

Derek Small
Derek Small
rbraha
Staff
Staff

Hi @DerekWSmall 

 

Token used for users on FGT can be managed  by FTC and with the same user with one token will be able to login in multiple devices , l am not aware of any option that you manage users in FTC and push them to individual FGT

DerekWSmall
New Contributor II

So I tried this, but when I add the user account to the second Fortigate, I get a second user in FTC with the same username and a different token serial number.  If I don't activate that Token, I cannot authentication with the token from the first Fortigate.  How do I add the user to the second Fortigate such that it uses the existing user in FTC, without creating a new one?  This is also consuming twice as many licenses in FTC.

Derek Small
Derek Small
DerekWSmall

Also, is there a way to make the local user accounts NOT case sensitive?  I'm fine with the passwords being case sensitive, but case really shouldn't matter for the username.

Derek Small
Derek Small
Labels
Top Kudoed Authors