FortiToken Cost Breakdown: What Fortinet MFA Really Costs vs Third-Party Solutions

Adding MFA to FortiGate should be straightforward. FortiGate is already on your network. Fortinet has its own MFA products — FortiToken Mobile and FortiToken 200 hardware — that integrate natively. No third-party tools, no RADIUS proxy, no extra infrastructure. That’s the pitch. The reality, for many organizations, is that native FortiToken licensing scales less predictably than expected — and FortiAuthenticator,...

Read More

VPN Attacks in 2026: Fortinet, Ivanti, Cisco — Why Passwords Are Not Enough

The three most widely deployed enterprise VPN platforms of the last decade — Fortinet FortiGate, Ivanti Connect Secure, and Cisco ASA — have together produced dozens of critical, actively exploited vulnerabilities between 2022 and 2026. Every major incident response firm has documented the campaigns. CISA has issued emergency directives. Patches have been released. And attackers are still getting in. Not always through new zero-days....

Read More
Azure MFA NPS Extension: Limitations, Costs & On-Prem Alternatives (2026)
Jul09

Azure MFA NPS Extension: Limitations, Costs & On-Prem Alternatives (2026)

The Azure MFA NPS Extension has been the go-to answer for adding a second factor to Microsoft NPS and securing VPN, Wi-Fi, and other network access protected by RADIUS authentication for years. It’s free (if you have the right license), it installs in under an hour, and it works. Until it doesn’t — and when it doesn’t, the failure mode is usually a structural one, not a configuration problem you can fix with a...

Read More
Host-Level vs Network-Level MFA: Credential Provider (RDP/Windows Logon) vs RADIUS Proxy (VPN/Wi-Fi)
Jul02

Host-Level vs Network-Level MFA: Credential Provider (RDP/Windows Logon) vs RADIUS Proxy (VPN/Wi-Fi)

Managing remote access security requires a decision most teams avoid until something goes wrong: where exactly should MFA be enforced? At the network edge, or on the host itself? The answer isn’t binary — but getting the layer wrong means either leaving critical servers exposed after a perimeter breach, or blocking legitimate administrators from getting in when the network stack misbehaves. This article breaks down the two...

Read More