Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
NeilG
Contributor

How do I use two factor authentication key with SSLVPN (client not the web portal)

If I use the SSLVPN portal page, and enter a valid user name and password I get prompted to enter the 2FA key.

 

With a Fortigate 60D with 5.2.0 build the web portal downloads the full SSLVPN client version 4.0.2300.0.

 

I am unable to authenticate because I never get prompted for the token-key.

 

I have tried combining the password and token-key as follows:

UserName

PasswordKeyValue

 

This has not worked.

 

Other info, no radius or LDAP involved.

User accounts are local.

 

If I use an account without two factor auth the client connects.

 

Any help would be great!

 

Thanks in advance.

-N

7 REPLIES 7
Baptiste
Contributor II

Hi,

With VPNSSL Client, you just have to configure your FQDN or IP address, your username and password.

Then click connect, connexion start, and you will be ask Fortitoken Code

 

If connexion fail, you have an error message, can you post it here ? and check at wich % connexion fail

2 FGT 100D  + FTK200

3 FGT 60E  FAZ VM  some FAP 210B/221C/223C/321C/421E

2 FGT 100D + FTK200 3 FGT 60E FAZ VM some FAP 210B/221C/223C/321C/421E
NeilG
Contributor

This is the SSLVPN client (not the forticlient)

 

I am prompted for server address, user name, password. There is no follow up prompt for the fortitoken-mobile code.

 

I have attached a screenshot of the screen.

NeilG
Contributor

Odd, I changed the port and now its working.

 

NeilG
Contributor

Of course now that I am getting prompted for the token, I still can't connect.

 

Where are the log files stored?

 

-Neil

Baptiste
Contributor II

can you post a screenshot with you error message ?

2 FGT 100D  + FTK200

3 FGT 60E  FAZ VM  some FAP 210B/221C/223C/321C/421E

2 FGT 100D + FTK200 3 FGT 60E FAZ VM some FAP 210B/221C/223C/321C/421E
NeilG
Contributor

Now I am having issues with the SSLVPN client package getting stuck at 98%, so no longer fortitoken mobile.

 

GRRR.

 

Why is the web (and thus probably the light weight sslvpn client) limited to Win7 as a newest supported Windows platform. GRRR.

 

I will get a screenshot when I can get back to that point. :(

-N

Christopher_McMullan

According to the release notes for FortiOS 5.2.0 GA, Windows support differs between the web portal and the standalone SSLVPN ('lite') client. The web portal does indeed support Windows 7 32- and 64-bit architecture, whereas the standalone client supports all architectures of Windows 8 on down, based on the 2303 installer.

Regards, Chris McMullan Fortinet Ottawa

Labels
Top Kudoed Authors