Hot!Fortigate SSL VPN with RSA SecurID as Multi-Factor-Authentication

Author
Alperen Uysal
New Member
  • Total Posts : 3
  • Scores: 0
  • Reward points: 0
  • Joined: 2020/07/09 06:58:55
  • Location: Germany
  • Status: offline
2020/07/12 23:28:45 (permalink) 6.0
0

Fortigate SSL VPN with RSA SecurID as Multi-Factor-Authentication

Hey guys,
 
I have to implement RSA SecurID as Multi-Factor-Authentication. I found guides how to do that on FortiOS 5.6 but not with the actual one. Maybe someone of you had to do the same and can help me out with this or has a guide how to do that.

All the guides use a local user bound to the RSA server but in my case I have a group that is bound to the AD with LDAP no local user. My problem is that I couldn't get it work that both of the authentication methods are used.
 
Thanks in advance!
 
 
#1

2 Replies Related Threads

    lobstercreed
    Platinum Member
    • Total Posts : 344
    • Scores: 43
    • Reward points: 0
    • Joined: 2018/11/28 14:57:58
    • Location: Sedalia, MO
    • Status: offline
    Re: Fortigate SSL VPN with RSA SecurID as Multi-Factor-Authentication 2020/07/13 03:59:47 (permalink)
    0
    I'm not familiar with RSA SecurID, but I assume the principles are largely the same as what we do with Okta.  Is RSA aware of your AD (i.e. can it do primary authentication)?  If so, you don't necessarily need "both", you just need the RSA server (RADIUS I assume?) to perform both factors before returning a successful login.
     
    In our case specifically we use Aruba ClearPass (RADIUS) to authenticate all our SSL-VPN.  When we added Okta it was as simple as adding Okta RADIUS to ClearPass where password and MFA was checked, then ClearPass used whatever other AD attributes it needed to determine what groups to send back to the FortiGate.
     
    I implemented on 6.0.9 though, and we're on 6.4.1 now.
    #2
    Haiqua
    New Member
    • Total Posts : 1
    • Scores: 0
    • Reward points: 0
    • Joined: 2020/10/22 00:33:26
    • Status: offline
    Re: Fortigate SSL VPN with RSA SecurID as Multi-Factor-Authentication 2020/10/22 00:53:04 (permalink)
    0
    I got the same problem. 
    Follow this post. 
    #3
    Jump to:
    © 2020 APG vNext Commercial Version 5.5