FortiOS 5.2 Authentication: Two-factor authentication with FortiToken Mobile

Source: Internet
Author: User
Keywords FortiToken Authentication
Tags forticloud fortios fortitoken fortitoken mobile fortigate authentication

Two-factor authentication requires a user to provide further means of authentication in addition to their credentials. In this recipe, FortiToken Mobile app for Android will be used to generate a token, also known as a one-time password (OTP), to use in the authentication process.

1. Activating your FortiTokens

Ensure that your FortiGate is connected to the Internet. Go to User & Device > FortiTokens. Your FortiGate may have two FortiToken Mobile entries listed by default. If so, you may use these tokens and go to step 2. 

To add new FortiTokens, select Create New. Set Type to Mobile Token and enter your Activation Code.

After FortiGuard validates the code, your FortiTokens will appear on the list, with Status set to Available.

2. Creating a user account with two-factor authentication

Go to User & Device > User > User Definition and create a new local user.

In order to use the FortiToken Mobile, you must enter a mobile number in the third step, Provide Contact Info. Select the appropriate Country/Region and enter the Phone Number without dashes or spaces. Do not add an email address.

In the fourth step of the User Creation Wizard, Provide Extra Info, enable Two-Factor Authentication and select an available token.

The user list shows the FortiToken in the Two-factor Authentication column for the new user account.

Go to User & Device > FortiTokens. The FortiToken assigned to the user is now listed as Pending, until the user activates the FortiToken.

3. Sending the activation code to the user

If your FortiGate can send SMS messages, go to User & Device > User > User Definition and edit the new user account. Select Send Activation Code and send the code by SMS.

If your FortiGate cannot send SMS messages, go to System > Dashboard > Status and enter the following into the CLI Console, substituting the correct serial number:

config user fortitoken
  edit <serial number>
  show

The activation code will be shown in the output. This code must be given to the user.

4. Adding user authentication to your Internet access policy

Go to Policy & Objects > Policy > IPv4 and edit the policy that allows connections from the internal network to the Internet. Set Source User(s) to the new user account.

5. Setting up FortiToken Mobile on an Android device

Using your Android device, download and install FortiToken Mobile. 

Open the app and add a new account. Select Enter Manually. Enter the activation code into FortiToken Mobile.

FortiToken Mobile can now generate a token for use with the FortiGate.

(Optional) For additional security, set a PIN for FortiToken Mobile using the app’s Settings options.

6. Results

Attempt to browse the Internet. An authentication page will appear, requesting a Username and Password.

After the correct username and password are entered, a FortiToken code will be requested. Enter the code currently shown in the FortiToken Mobile app. Once the token is authenticated, you can connect to the Internet.

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.