Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Alperen_Uysal
New Contributor

Fortigate SSL VPN with RSA SecurID as Multi-Factor-Authentication

Hey guys,

 

I have to implement RSA SecurID as Multi-Factor-Authentication. I found guides how to do that on FortiOS 5.6 but not with the actual one. Maybe someone of you had to do the same and can help me out with this or has a guide how to do that. All the guides use a local user bound to the RSA server but in my case I have a group that is bound to the AD with LDAP no local user. My problem is that I couldn't get it work that both of the authentication methods are used.

 

Thanks in advance!

 

 

2 REPLIES 2
lobstercreed
Valued Contributor

I'm not familiar with RSA SecurID, but I assume the principles are largely the same as what we do with Okta.  Is RSA aware of your AD (i.e. can it do primary authentication)?  If so, you don't necessarily need "both", you just need the RSA server (RADIUS I assume?) to perform both factors before returning a successful login.

 

In our case specifically we use Aruba ClearPass (RADIUS) to authenticate all our SSL-VPN.  When we added Okta it was as simple as adding Okta RADIUS to ClearPass where password and MFA was checked, then ClearPass used whatever other AD attributes it needed to determine what groups to send back to the FortiGate.

 

I implemented on 6.0.9 though, and we're on 6.4.1 now.

Haiqua
New Contributor

I got the same problem. 

Follow this post. 

Labels
Top Kudoed Authors