FortiGate: 2FA for FortiClient VPN by FortiToken (Mobile App)

FortiGate: 2FA for FortiClient VPN by FortiToken (Mobile App)
Photo by Dan Nelson / Unsplash

To enable 2FA using FortiToken (Mobile App). The default licenses from the box allow you to use for 2 accounts. More than 2 accounts are required to purchase the licenses. To set up 2FA use with FortiToken, try to following steps.

  1. Log in to the FortiGate web console.

  1. Go to "User & Authentication" > "User Definition" > Select the user and "Edit".

  1. Enable "Two-factor Authentication".
  2. Authentication Type = FortiToken
  3. Token = "Select 1 of 2" (1 for each user).

  1. Enter the email address used to receive the active code and save.

  1. Token will show on the user.

  1. Select this user and "Edit".
  2. Send Activation Code Email.

  1. Check your email inbox. It should receive the email about activation on FortiGate.

  1. Download the application on your mobile phone named "FortiToken" (supports iOS and Android).

  1. Open app "FortiToken Mobile"
  2. On the first time opening this app. "Scan or enter key to add token".

  1. Select "SCAN BARCODE". Then scan the barcode that it sent to your email.
  2. After that, the Token will be added to the app on your mobile phone.
  3. Use the code on the mobile app as 2FA when you log in to FortiClient.
  4. Test connecting FortiClient VPN. After entering a username and password, Token box will appear.

  1. Open the app "FortiToken" on your mobile, use the token code to enter on FortiClient VPN.

  1. Now you can connect the FortiClient with 2FA via FortiToken (Mobile app).