0D51Y00006kfcDBSAYOkta Classic EngineSingle Sign-OnAnswered2024-04-16T09:56:55.000Z2019-10-11T02:00:24.000Z2021-02-02T21:53:02.000Z

g80fz (g80fz) asked a question.

Configuring Okta for Fortigate VPN authentication like DUO

We followed the following guide and no success. Not sure if we're missing something. We currently use DUO/ipsec for our Fortigate VPN and that works flawlessly. Not sure if Okta offers ipsec.....

 

 

Also not sure what VPN settings I have to setup/configure in Fortigate VPN app. It wasn't mentioned in the guide.

 

 

If anyone could help that would be really great and helpful! ^^


    • g80fz (g80fz)

      My answer is still not resolved. The Okta support technician can’t even figure it out….. and were guaranteed this would work for us. This is a REAL deal breaker for us and if this doesn’t work then we won’t be switching from DUO.

      Thanks,
      Sumi
      Expand Post
  • d6q2d (d6q2d)

    Hey @g80fz (g80fz)​ 

     

    I am facing same issue. Did you got any luck with IPSEC VPN on Fortigate ?

     

     

    • g80fz (g80fz)

      Hi Jay,

      Yes we figured it out. But unfortunately we couldn’t go with Okta due to the fact that they only offered PAP.

      So if you wish to use IPsec then you would need to go to VPN > IPsec Tunnels on Fortigate. Make sure the authentication method is set to Pre-shared key. For XAUTH, the type needs to be set to PAP server and the User group set to your Firewall group that you need to create.

      Thanks,
      Sumi
      Expand Post
  • d6q2d (d6q2d)

    @g80fz (g80fz)​ 

     

    So you mean we have to create local group on Firewall ?

  • d6q2d (d6q2d)

    @g80fz (g80fz)​  Thank you for response. I think I got little confused here. So does Fortinet IPSEC VPN works with OKTA or not ?

    • g80fz (g80fz)

      Yes. But only if your company allows PAP authentication. Which is the lowest of the low and isn’t recommended. We would have bought Okta in a heartbeat if only it supported MSCHAPv2.

      Thanks,
      Sumi
      Expand Post
This question is closed.

Recommended content