MFA for FortiGate: Two-Factor Authentication Without FortiToken Pricing
FortiGate is the most widely deployed next-generation firewall in the enterprise market — and for the last four years, it has also been one of the most consistently targeted. The SSL VPN interface, the management console, and the FortiOS core have each produced critical vulnerabilities that attackers have exploited within days of disclosure, sometimes before patches were even available.
Passwords alone do not protect a FortiGate VPN. The credential attacks documented against Fortinet devices in 2024–2026 didn’t require vulnerability exploitation — they used valid usernames and passwords obtained from phishing, credential stuffing, or configuration file leaks from previously compromised devices.
Quick Answer
Protectimus adds MFA to FortiGate SSL VPN, IPsec VPN, and admin access through a Protectimus RADIUS Server — TOTP apps and hardware tokens, SMS, chatbots, and email OTP, no FortiToken per-user licenses required. Standard single-gateway deployment completes in one day.
Key facts
MFA blocks over 99.2% of automated credential attacks
Microsoft’s Digital Defense Report 2025 found that MFA remains the single highest-impact control against credential-based intrusions — the attack type that most directly targets FortiGate VPN endpoints. (Microsoft Digital Defense Report)
26 Fortinet CVEs in the CISA Known Exploited Vulnerabilities catalog
As of July 2026, CISA has confirmed 26 Fortinet vulnerabilities actively exploited in the wild — more than any other network security vendor in the catalog. The most recent, CVE-2025-59718 (CVSS 9.1), allowed unauthenticated attackers to bypass FortiCloud SSO entirely via crafted SAML messages. CISA issued a 7-day patch deadline upon adding it to the KEV. (CISA Known Exploited Vulnerabilities Catalog, July 2026)
FortiGate SSL VPN: the most exploited perimeter device of 2024–2025
CVE-2022-42475, CVE-2023-27997, and CVE-2024-21762 — all FortiOS SSL VPN vulnerabilities — were chained in a multi-year persistence campaign where attackers maintained read-only access to device configurations even after patches were applied. Threat actor Mora_001 (linked to LockBit) exploited CVE-2024-55591 and CVE-2025-24472 to gain super-admin privileges on internet-exposed FortiGate devices and deploy ransomware. (Fortinet PSIRT advisory, April 2025; CISA Alert, April 2025; Forescout Vedere Labs, 2025)
Key Takeaways
One MFA server for your entire network stack
The same Protectimus RADIUS deployment can protect FortiGate alongside Cisco, Palo Alto, SonicWall, Check Point, Juniper, F5, Citrix ADC, and other RADIUS-enabled systems
RADIUS integration, no FortiToken licenses
Protectimus connects to FortiGate as a standard RADIUS server; no per-user FortiToken licenses, no FortiAuthenticator appliance required.
SSL VPN, IPsec VPN, and admin login
All three FortiGate access paths covered from a single deployment.
Hardware OTP token support
Including programmable NFC tokens as a direct alternative to FortiToken 200.
On-premises or cloud
Deploy the Protectimus server inside your network perimeter or use the cloud service.
Works with FortiClient
Standard FortiClient authentication flow, no client-side changes.
Why FortiGate VPN Needs MFA Beyond Passwords
FortiGate’s SSL VPN interface has produced more critical, actively exploited vulnerabilities than almost any other enterprise security product in recent years. CVE-2018-13379 leaked VPN credentials for approximately 50,000 devices. CVE-2022-42475, CVE-2023-27997, and CVE-2024-21762 enabled remote code execution via the SSL VPN daemon with no authentication required. CVE-2024-55591 and CVE-2025-24472 granted super-admin privileges through the management WebSocket interface.
The April 2025 Fortinet advisory described the outcome of this vulnerability chain directly: attackers created a symbolic link between the SSL VPN user file system and the root file system, maintaining read-only access to device configurations — including credentials — even after the original vulnerabilities were patched. Organizations that patched promptly were still exposed to ongoing credential harvesting from their own devices.
Amazon Threat Intelligence documented a separate campaign in early 2026: a financially motivated threat actor using commercial AI tools to systematically compromise over 600 FortiGate devices across 55 countries. The initial access vector was credential-based — not exploitation — targeting management interfaces exposed to the internet.
Vulnerability patching and credential hygiene are necessary but not sufficient. An attacker with a valid username and password — from a phishing campaign, a credential list, or a leaked configuration file — bypasses every defense that depends on patched vulnerabilities. MFA enforced at the authentication layer means that a stolen password alone cannot open a VPN session.
FortiToken vs Third-Party MFA: The Real Cost
Fortinet’s native MFA products — FortiToken Mobile, FortiToken 200 hardware, and FortiAuthenticator — are purpose-built for the FortiGate ecosystem and work without a separate RADIUS server. But their licensing model creates real operational constraints.
FortiToken Mobile requires a perpetual per-user license registered to a specific FortiGate appliance. Licenses are non-transferable between devices (for licenses issued after August 2025). If you have multiple FortiGate units across locations, you need separate license pools per appliance unless you centralize through FortiAuthenticator.
FortiToken 200 (hardware token) is a physical OATH TOTP device, also licensed per unit and tied to a specific appliance. Replacing lost tokens means purchasing new licenses. Seed files are encrypted and available only through Fortinet customer support.
FortiAuthenticator is a separate appliance (physical or virtual) that centralizes token management across multiple FortiGate units. It resolves the per-appliance license problem but adds deployment complexity, licensing cost, and another piece of infrastructure to maintain and patch.
The structural difference with a third-party RADIUS proxy approach:
Factor | FortiToken Mobile | FortiToken 200 | Protectimus (RADIUS proxy) |
|---|---|---|---|
License model | Perpetual per-user, per-appliance | Perpetual per-unit, per-appliance | Subscription per-user, appliance-independent |
License transfer | Not allowed (post Aug 2025) | Not allowed | Not applicable |
Multi-appliance support | Requires FortiAuthenticator | Requires FortiAuthenticator | Native — one server, multiple gateways |
Supported authentication methods | FortiToken Mobile (TOTP), FortiToken 200 | FortiToken 200 | TOTP apps, SMS, email, chatbots, and OATH-compliant hardware tokens (TOTP, HOTP, and OCRA) |
Programmable tokens | No | No | Yes (Slim NFC and Flex) |
Covers non-Fortinet devices | No | No | Yes — Cisco, Palo Alto, etc. |
Additional MFA server needed | No (for single appliance) | No (for single appliance) | Yes (Protectimus server) |
The trade-off is straightforward: FortiToken is simpler for a single FortiGate deployment with a stable user population. Protectimus becomes more cost-effective when you have multiple FortiGate gateways, heterogeneous network infrastructure, broader authentication requirements (SMS, email, chatbots, or OATH hardware tokens), or need to protect non-Fortinet systems with the same MFA deployment.
How Protectimus MFA Works with FortiGate
Protectimus integrates with FortiGate as a standard RADIUS authentication server. FortiGate communicates with Protectimus as with any standard RADIUS server. It sends authentication requests exactly as it would to any other RADIUS server.
Authentication flow
FortiClient / Browser
SSL VPN / IPsec VPN / Admin Login
or Protectimus On-Premise Platform
Validates credentials via AD, LDAP, or another configured authentication provider
Prompts the user for an OTP
Enters a one-time password
or Protectimus On-Premise Platform
Validates the OTP
Returns RADIUS Access-Accept
Establishes the VPN or administrator session
FortiGate configuration overview
On the FortiGate side, the configuration involves three components:
RADIUS server definition. Add Protectimus as a RADIUS server under User & Authentication → RADIUS Servers. Set the server IP, shared secret, and authentication method (PAP). Increase the server timeout to at least 30 seconds — the default 5-second timeout causes authentication failures when users take longer than that to retrieve their OTP.
User group. Create or modify a user group that references the Protectimus RADIUS server as the remote authentication source. SSL VPN policies and admin profiles will reference this group.
SSL VPN / firewall policy assignment. Assign the RADIUS-authenticated user group to the relevant SSL VPN portal and firewall policies.
For the complete configuration with CLI commands and screenshots, see the full FortiGate 2FA setup guide.
Access-Challenge and Inline Mode
FortiGate supports RADIUS Access-Challenge in its SSL VPN web portal and tunnel mode clients. When the Access-Challenge is issued, FortiClient presents a secondary OTP input field to the user after the password is accepted.
For configurations where challenge/response creates issues — certain FortiClient versions or IPsec authentication paths — Protectimus supports Inline Mode: the user enters password and OTP in a single field with a configured separator (for example, MyPassword,123456). The Protectimus server parses the combined input and validates each component separately.
What You Can Protect
A single Protectimus RADIUS deployment covers all FortiGate authentication surfaces:
SSL VPN — the primary remote access path. Both web portal (browser-based) and tunnel mode (FortiClient) authentication go through the RADIUS server. This is the highest-risk surface given the SSL VPN vulnerability history.
IPsec VPN — site-to-site and client-to-site IPsec configurations that use XAUTH or IKEv1/IKEv2 with RADIUS authentication. IPsec deployments that rely only on a pre-shared key don’t require user authentication, but configurations using XAuth or EAP with RADIUS can authenticate users through Protectimus. This covers remote workers using FortiClient with IPsec tunnel mode as an alternative to SSL VPN.
FortiGate admin login — the management GUI (HTTPS) and SSH administrative access. FortiOS supports RADIUS authentication for admin accounts, allowing the same MFA enforcement on administrative sessions that applies to VPN users. Admin accounts represent the highest-value target — super-admin access gives complete control over firewall rules, VPN configuration, and logging.
FortiClient EMS deployments — FortiClient EMS-managed VPN deployments can use the same Protectimus RADIUS server for authentication.
Supported Authentication Methods
Method | Delivery | Best for |
|---|---|---|
Authenticator app, 30-second codes | Most enterprise users with smartphones | |
Programmable NFC card-format token (TOTP) | Organizations requiring reusable hardware tokens; direct alternative to FortiToken 200 | |
Programmable NFC key-fob hardware token (TOTP) | Organizations requiring reusable hardware tokens; direct alternative to FortiToken 200 | |
Classic TOTP tokens in a key-fob form factor | Users without smartphones; high-security roles | |
6-digit code via SMS | Users without smartphones or reliable Internet access | |
6-digit code via email | Organizations that prefer email-based OTP delivery | |
OTP via Telegram, Viber or Facebook Messenger | Organizations looking for a convenient, low-cost alternative to SMS OTP |
Note on hardware tokens: The Protectimus Slim NFC and Protectimus FLEX are programmable OATH TOTP tokens — the closest functional equivalents to the FortiToken 200, but with a key difference: the seed can be reprogrammed. When a user leaves the organization, the token can be reassigned and re-enrolled rather than replaced. Any OATH-compliant TOTP, HOTP, or OCRA hardware token also works.
For the full hardware TOTP tokens portfolio, see the tokens page.
Step-by-Step: FortiGate MFA in 4 Steps
Step 1 — Deploy Protectimus. Choose the Protectimus Cloud Service or On-Premise Platform. Install and configure the Protectimus RADIUS Server inside your network. For an on-premises deployment, install both the Protectimus On-Premise Platform and the Protectimus RADIUS Server, then configure Active Directory or LDAP synchronization if required. See the on-premises MFA platform page for system requirements.
Step 2 — Add Protectimus as a RADIUS server on FortiGate. In the FortiGate web UI: User & Authentication → RADIUS Servers → Create New. Enter the Protectimus server IP, set a strong shared secret, select PAP as the authentication method, and set the timeout to 30 seconds. Test the connection to confirm RADIUS communication is working.
Step 3 — Configure user group and authentication policy. Create a user group referencing the Protectimus RADIUS server. Assign this group to the SSL VPN portal, tunnel mode policy, or admin profile as appropriate. For admin login MFA, edit the admin account under System → Administrators and set the authentication to use the RADIUS-authenticated group.
Step 4 — Enroll users and test. Send self-enrollment links to a pilot group. Users register their authenticator app by scanning a QR code, or receive a hardware token assignment. Test the full flow: connect via SSL VPN, enter credentials, confirm the OTP prompt appears, verify successful session establishment. Then extend enrollment to the full user population.
For CLI commands, specific FortiOS version notes, and IPsec configuration, see the full FortiGate 2FA setup guide.
Compliance
PCI DSS v4.0 (Requirements 8.4.2 and 8.4.3)
Requirement 8.4.3 mandates MFA for all remote access to the cardholder data environment originating from outside the organization’s network. FortiGate SSL VPN and IPsec VPN connections into environments that touch payment systems fall directly under this requirement. Requirement 8.4.2 extends MFA requirements to access into the cardholder data environment, including admin login to FortiGate devices that manage in-scope network segments.
NIST SP 800-63B (AAL2)
Authenticator Assurance Level 2 requires two distinct authentication factors for access to sensitive systems. TOTP via authenticator app or hardware token satisfies AAL2 — the password is the memorized secret, the token is the bound authenticator.
NIS2 Directive (Article 21)
Essential and important entities in EU member states must implement MFA or continuous authentication for access to network and information systems. FortiGate VPN access to internal infrastructure is explicitly in scope.
ISO/IEC 27001:2022 (Annex A 8.5)
Secure authentication controls are explicitly recommended for remote access and administrative account scenarios.
Cyber insurance requirements
MFA on remote access — specifically VPN and RDP — has become a standard underwriting requirement for cyber liability policies. FortiGate SSL VPN without MFA is frequently flagged in pre-binding security assessments and can result in either policy denial or significantly higher premiums. Demonstrating MFA enforcement via RADIUS directly satisfies this requirement in most policy applications. Following the widely reported FortiGate exploitation campaigns of 2024–2025, some insurers have begun requiring documented evidence of MFA on perimeter devices as a condition of renewal, not just initial binding.
FAQ
Does Protectimus replace FortiToken?
Yes, it replaces FortiToken as the MFA mechanism for FortiGate authentication. Users enroll in Protectimus instead of FortiToken and use a Protectimus-compatible authenticator app or hardware token. FortiToken licenses are not required.
Do I need FortiAuthenticator to use Protectimus with FortiGate?
No. FortiAuthenticator is Fortinet’s centralized MFA management server — it’s commonly used to centrally manage FortiToken authentication across multiple FortiGate appliances. Protectimus functions as a RADIUS server that FortiGate talks to directly, without FortiAuthenticator in the chain.
Does it work with FortiClient?
Yes. FortiClient uses the standard FortiGate SSL VPN authentication flow, which routes through RADIUS. FortiGate sends the RADIUS authentication request to Protectimus, which enforces MFA exactly as it does for web portal connections. No FortiClient configuration changes are required.
Does it cover both SSL VPN and IPsec VPN?
Yes. SSL VPN (both web portal and tunnel mode) and user-authenticated IPsec VPN configurations both support RADIUS authentication on FortiGate. A single Protectimus RADIUS server handles both.
Is there a hardware token option as an alternative to FortiToken 200?
Yes. The Protectimus Slim NFC and Protectimus FLEX are programmable OATH TOTP tokens in card format and key-fob format — functionally equivalent to FortiToken 200 but re-programmable, which means these OTP token models can be reassigned to a new user rather than replaced when an employee leaves. Any OATH TOTP, HOTP, or OCRA-compatible hardware token also works.
What happens if the Protectimus MFA server goes down?
Configure a primary and secondary Protectimus RADIUS server. FortiGate’s RADIUS failover switches to the secondary server automatically if the primary doesn’t respond within the timeout. For on-premises deployments, both servers should be on different hosts in separate availability zones or physical locations.
Can one Protectimus server cover Cisco, Palo Alto, or SonicWall alongside FortiGate?
Yes. Protectimus works with standard RADIUS clients compliant with RFC 2865. A single deployment can simultaneously serve FortiGate, Cisco ASA/FTD, Palo Alto GlobalProtect, SonicWall, and other RADIUS-authenticated services. Users enroll once and their token works across all gateways. See RADIUS authentication with MFA and MFA for VPN for the broader architecture.
Start Securing FortiGate Today
FortiGate is a high-value target. The SSL VPN vulnerability history and the documented credential-based campaigns of 2024–2026 make password-only VPN authentication an accepted risk that’s difficult to justify to auditors, insurers, or incident response teams after the fact.
Protectimus adds MFA to FortiGate in one day without replacing your gateway, without FortiToken per-user licenses, and without FortiAuthenticator.
Start for free — up to 10 users plus $25 in testing credit. No credit card required.