MFA for FortiGate: Two-Factor Authentication Without FortiToken Pricing

FortiGate is the most widely deployed next-generation firewall in the enterprise market — and for the last four years, it has also been one of the most consistently targeted. The SSL VPN interface, the management console, and the FortiOS core have each produced critical vulnerabilities that attackers have exploited within days of disclosure, sometimes before patches were even available.

Passwords alone do not protect a FortiGate VPN. The credential attacks documented against Fortinet devices in 2024–2026 didn’t require vulnerability exploitation — they used valid usernames and passwords obtained from phishing, credential stuffing, or configuration file leaks from previously compromised devices.

Quick Answer

 Protectimus adds MFA to FortiGate SSL VPN, IPsec VPN, and admin access through a Protectimus RADIUS Server — TOTP apps and hardware tokens, SMS, chatbots, and email OTP, no FortiToken per-user licenses required. Standard single-gateway deployment completes in one day.

Key facts

MFA blocks over 99.2% of automated credential attacks

Microsoft

Microsoft’s Digital Defense Report 2025 found that MFA remains the single highest-impact control against credential-based intrusions — the attack type that most directly targets FortiGate VPN endpoints. (Microsoft Digital Defense Report)

26 Fortinet CVEs in the CISA Known Exploited Vulnerabilities catalog

CISA

As of July 2026, CISA has confirmed 26 Fortinet vulnerabilities actively exploited in the wild — more than any other network security vendor in the catalog. The most recent, CVE-2025-59718 (CVSS 9.1), allowed unauthenticated attackers to bypass FortiCloud SSO entirely via crafted SAML messages. CISA issued a 7-day patch deadline upon adding it to the KEV.  (CISA Known Exploited Vulnerabilities Catalog, July 2026)

FortiGate SSL VPN: the most exploited perimeter device of 2024–2025

Fortinet

CVE-2022-42475, CVE-2023-27997, and CVE-2024-21762 — all FortiOS SSL VPN vulnerabilities — were chained in a multi-year persistence campaign where attackers maintained read-only access to device configurations even after patches were applied. Threat actor Mora_001 (linked to LockBit) exploited CVE-2024-55591 and CVE-2025-24472 to gain super-admin privileges on internet-exposed FortiGate devices and deploy ransomware. (Fortinet PSIRT advisory, April 2025; CISA Alert, April 2025; Forescout Vedere Labs, 2025)

Key Takeaways

On-Premise MFA Platform – Security feature: A Cluster-Based, Fault-Tolerant System

One MFA server for your entire network stack

The same Protectimus RADIUS deployment can protect FortiGate alongside Cisco, Palo Alto, SonicWall, Check Point, Juniper, F5, Citrix ADC, and other RADIUS-enabled systems

RADIUS MFA icon

RADIUS integration, no FortiToken licenses

Protectimus connects to FortiGate as a standard RADIUS server; no per-user FortiToken licenses, no FortiAuthenticator appliance required.

VPN MFA icon

SSL VPN, IPsec VPN, and admin login

All three FortiGate access paths covered from a single deployment.

On-Prem MFA Platform icon

Hardware OTP token support

Including programmable NFC tokens as a direct alternative to FortiToken 200.

On-premise MFA platform icon

On-premises or cloud

Deploy the Protectimus server inside your network perimeter or use the cloud service.

Customer Stories section icon – real-life client experiences

Works with FortiClient

Standard FortiClient authentication flow, no client-side changes.

Why FortiGate VPN Needs MFA Beyond Passwords

FortiGate’s SSL VPN interface has produced more critical, actively exploited vulnerabilities than almost any other enterprise security product in recent years. CVE-2018-13379 leaked VPN credentials for approximately 50,000 devices. CVE-2022-42475, CVE-2023-27997, and CVE-2024-21762 enabled remote code execution via the SSL VPN daemon with no authentication required. CVE-2024-55591 and CVE-2025-24472 granted super-admin privileges through the management WebSocket interface.

The April 2025 Fortinet advisory described the outcome of this vulnerability chain directly: attackers created a symbolic link between the SSL VPN user file system and the root file system, maintaining read-only access to device configurations — including credentials — even after the original vulnerabilities were patched. Organizations that patched promptly were still exposed to ongoing credential harvesting from their own devices.

Amazon Threat Intelligence documented a separate campaign in early 2026: a financially motivated threat actor using commercial AI tools to systematically compromise over 600 FortiGate devices across 55 countries. The initial access vector was credential-based — not exploitation — targeting management interfaces exposed to the internet.

Vulnerability patching and credential hygiene are necessary but not sufficient. An attacker with a valid username and password — from a phishing campaign, a credential list, or a leaked configuration file — bypasses every defense that depends on patched vulnerabilities. MFA enforced at the authentication layer means that a stolen password alone cannot open a VPN session.

FortiToken vs Third-Party MFA: The Real Cost

Fortinet’s native MFA products — FortiToken Mobile, FortiToken 200 hardware, and FortiAuthenticator — are purpose-built for the FortiGate ecosystem and work without a separate RADIUS server. But their licensing model creates real operational constraints.

FortiToken Mobile requires a perpetual per-user license registered to a specific FortiGate appliance. Licenses are non-transferable between devices (for licenses issued after August 2025). If you have multiple FortiGate units across locations, you need separate license pools per appliance unless you centralize through FortiAuthenticator.

FortiToken 200 (hardware token) is a physical OATH TOTP device, also licensed per unit and tied to a specific appliance. Replacing lost tokens means purchasing new licenses. Seed files are encrypted and available only through Fortinet customer support.

FortiAuthenticator is a separate appliance (physical or virtual) that centralizes token management across multiple FortiGate units. It resolves the per-appliance license problem but adds deployment complexity, licensing cost, and another piece of infrastructure to maintain and patch.

The structural difference with a third-party RADIUS proxy approach:

 

Factor

FortiToken Mobile

FortiToken 200

Protectimus (RADIUS proxy)

License model

Perpetual per-user, per-appliance

Perpetual per-unit, per-appliance

Subscription per-user, appliance-independent

License transfer

Not allowed (post Aug 2025)

Not allowed

Not applicable

Multi-appliance support

Requires FortiAuthenticator

Requires FortiAuthenticator

Native — one server, multiple gateways

Supported authentication methods

FortiToken Mobile (TOTP), FortiToken 200

FortiToken 200

TOTP apps, SMS, email, chatbots, and OATH-compliant hardware tokens (TOTP, HOTP, and OCRA)

Programmable tokens

No

No

Yes (Slim NFC and Flex)

Covers non-Fortinet devices

No

No

Yes — Cisco, Palo Alto, etc.

Additional MFA server needed

No (for single appliance)

No (for single appliance)

Yes (Protectimus server)

 

The trade-off is straightforward: FortiToken is simpler for a single FortiGate deployment with a stable user population. Protectimus becomes more cost-effective when you have multiple FortiGate gateways, heterogeneous network infrastructure, broader authentication requirements (SMS, email, chatbots, or OATH hardware tokens), or need to protect non-Fortinet systems with the same MFA deployment.

How Protectimus MFA Works with FortiGate

Protectimus integrates with FortiGate as a standard RADIUS authentication server. FortiGate communicates with Protectimus as with any standard RADIUS server. It sends authentication requests exactly as it would to any other RADIUS server.


Authentication flow

User
FortiClient / Browser
Enters username and password
FortiGate
SSL VPN / IPsec VPN / Admin Login
RADIUS Access-Request (username + password)
Protectimus RADIUS Server
Protectimus Cloud Service
or Protectimus On-Premise Platform

Validates credentials via AD, LDAP, or another configured authentication provider
Password valid — RADIUS Access-Challenge returned
FortiGate
Prompts the user for an OTP
OTP prompt is displayed
User
Enters a one-time password
RADIUS Access-Request (OTP)
Protectimus RADIUS Server
Protectimus Cloud Service
or Protectimus On-Premise Platform

Validates the OTP

Returns RADIUS Access-Accept
RADIUS Access-Accept returned to FortiGate
FortiGate
Establishes the VPN or administrator session

FortiGate configuration overview

On the FortiGate side, the configuration involves three components:

RADIUS server definition. Add Protectimus as a RADIUS server under User & Authentication → RADIUS Servers. Set the server IP, shared secret, and authentication method (PAP). Increase the server timeout to at least 30 seconds — the default 5-second timeout causes authentication failures when users take longer than that to retrieve their OTP.

User group. Create or modify a user group that references the Protectimus RADIUS server as the remote authentication source. SSL VPN policies and admin profiles will reference this group.

SSL VPN / firewall policy assignment. Assign the RADIUS-authenticated user group to the relevant SSL VPN portal and firewall policies.

For the complete configuration with CLI commands and screenshots, see the full FortiGate 2FA setup guide.


Access-Challenge and Inline Mode

FortiGate supports RADIUS Access-Challenge in its SSL VPN web portal and tunnel mode clients. When the Access-Challenge is issued, FortiClient presents a secondary OTP input field to the user after the password is accepted.

For configurations where challenge/response creates issues — certain FortiClient versions or IPsec authentication paths — Protectimus supports Inline Mode: the user enters password and OTP in a single field with a configured separator (for example, MyPassword,123456). The Protectimus server parses the combined input and validates each component separately.

What You Can Protect

A single Protectimus RADIUS deployment covers all FortiGate authentication surfaces:

SSL VPN — the primary remote access path. Both web portal (browser-based) and tunnel mode (FortiClient) authentication go through the RADIUS server. This is the highest-risk surface given the SSL VPN vulnerability history.

IPsec VPN — site-to-site and client-to-site IPsec configurations that use XAUTH or IKEv1/IKEv2 with RADIUS authentication. IPsec deployments that rely only on a pre-shared key don’t require user authentication, but configurations using XAuth or EAP with RADIUS can authenticate users through Protectimus. This covers remote workers using FortiClient with IPsec tunnel mode as an alternative to SSL VPN.

FortiGate admin login — the management GUI (HTTPS) and SSH administrative access. FortiOS supports RADIUS authentication for admin accounts, allowing the same MFA enforcement on administrative sessions that applies to VPN users. Admin accounts represent the highest-value target — super-admin access gives complete control over firewall rules, VPN configuration, and logging.

FortiClient EMS deployments — FortiClient EMS-managed VPN deployments can use the same Protectimus RADIUS server for authentication.

Supported Authentication Methods

Method

Delivery

Best for

TOTP via Protectimus SMART app

Authenticator app, 30-second codes

Most enterprise users with smartphones

Slim NFC hardware token

Programmable NFC card-format token (TOTP)

Organizations requiring reusable hardware tokens; direct alternative to FortiToken 200

FLEX hardware token

Programmable NFC key-fob hardware token (TOTP)

Organizations requiring reusable hardware tokens; direct alternative to FortiToken 200

TWO / SHARK hardware tokens

Classic TOTP tokens in a key-fob form factor 

Users without smartphones; high-security roles

SMS OTP

6-digit code via SMS

Users without smartphones or reliable Internet access

Email OTP

6-digit code via email

Organizations that prefer email-based OTP delivery

Chatbot OTP

OTP via Telegram, Viber or Facebook Messenger

Organizations looking for a convenient, low-cost alternative to SMS OTP

 

Note on hardware tokens: The Protectimus Slim NFC and Protectimus FLEX are programmable OATH TOTP tokens — the closest functional equivalents to the FortiToken 200, but with a key difference: the seed can be reprogrammed. When a user leaves the organization, the token can be reassigned and re-enrolled rather than replaced. Any OATH-compliant TOTP, HOTP, or OCRA hardware token also works.

For the full hardware TOTP tokens portfolio, see the tokens page.

Step-by-Step: FortiGate MFA in 4 Steps

Step 1 — Deploy Protectimus. Choose the Protectimus Cloud Service or On-Premise Platform. Install and configure the Protectimus RADIUS Server inside your network. For an on-premises deployment, install both the Protectimus On-Premise Platform and the Protectimus RADIUS Server, then configure Active Directory or LDAP synchronization if required. See the on-premises MFA platform page for system requirements.

Step 2 — Add Protectimus as a RADIUS server on FortiGate. In the FortiGate web UI: User & Authentication → RADIUS Servers → Create New. Enter the Protectimus server IP, set a strong shared secret, select PAP as the authentication method, and set the timeout to 30 seconds. Test the connection to confirm RADIUS communication is working.

Step 3 — Configure user group and authentication policy. Create a user group referencing the Protectimus RADIUS server. Assign this group to the SSL VPN portal, tunnel mode policy, or admin profile as appropriate. For admin login MFA, edit the admin account under System → Administrators and set the authentication to use the RADIUS-authenticated group. 

Step 4 — Enroll users and test. Send self-enrollment links to a pilot group. Users register their authenticator app by scanning a QR code, or receive a hardware token assignment. Test the full flow: connect via SSL VPN, enter credentials, confirm the OTP prompt appears, verify successful session establishment. Then extend enrollment to the full user population.

For CLI commands, specific FortiOS version notes, and IPsec configuration, see the full FortiGate 2FA setup guide.

Compliance

PCI DSS v4.0 (Requirements 8.4.2 and 8.4.3) 

Requirement 8.4.3 mandates MFA for all remote access to the cardholder data environment originating from outside the organization’s network. FortiGate SSL VPN and IPsec VPN connections into environments that touch payment systems fall directly under this requirement. Requirement 8.4.2 extends MFA requirements to access into the cardholder data environment, including admin login to FortiGate devices that manage in-scope network segments.

NIST SP 800-63B (AAL2) 

Authenticator Assurance Level 2 requires two distinct authentication factors for access to sensitive systems. TOTP via authenticator app or hardware token satisfies AAL2 — the password is the memorized secret, the token is the bound authenticator.

NIS2 Directive (Article 21) 

Essential and important entities in EU member states must implement MFA or continuous authentication for access to network and information systems. FortiGate VPN access to internal infrastructure is explicitly in scope.

ISO/IEC 27001:2022 (Annex A 8.5) 

Secure authentication controls are explicitly recommended for remote access and administrative account scenarios.

Cyber insurance requirements 

MFA on remote access — specifically VPN and RDP — has become a standard underwriting requirement for cyber liability policies. FortiGate SSL VPN without MFA is frequently flagged in pre-binding security assessments and can result in either policy denial or significantly higher premiums. Demonstrating MFA enforcement via RADIUS directly satisfies this requirement in most policy applications. Following the widely reported FortiGate exploitation campaigns of 2024–2025, some insurers have begun requiring documented evidence of MFA on perimeter devices as a condition of renewal, not just initial binding.

FAQ

Yes, it replaces FortiToken as the MFA mechanism for FortiGate authentication. Users enroll in Protectimus instead of FortiToken and use a Protectimus-compatible authenticator app or hardware token. FortiToken licenses are not required.

No. FortiAuthenticator is Fortinet’s centralized MFA management server — it’s commonly used to centrally manage FortiToken authentication across multiple FortiGate appliances. Protectimus functions as a RADIUS server that FortiGate talks to directly, without FortiAuthenticator in the chain.

Yes. FortiClient uses the standard FortiGate SSL VPN authentication flow, which routes through RADIUS. FortiGate sends the RADIUS authentication request to Protectimus, which enforces MFA exactly as it does for web portal connections. No FortiClient configuration changes are required.

Yes. SSL VPN (both web portal and tunnel mode) and user-authenticated IPsec VPN configurations both support RADIUS authentication on FortiGate. A single Protectimus RADIUS server handles both.

Yes. The Protectimus Slim NFC and Protectimus FLEX are programmable OATH TOTP tokens in card format and key-fob format — functionally equivalent to FortiToken 200 but re-programmable, which means these OTP token models can be reassigned to a new user rather than replaced when an employee leaves. Any OATH TOTP, HOTP, or OCRA-compatible hardware token also works.

Configure a primary and secondary Protectimus RADIUS server. FortiGate’s RADIUS failover switches to the secondary server automatically if the primary doesn’t respond within the timeout. For on-premises deployments, both servers should be on different hosts in separate availability zones or physical locations.

Yes. Protectimus works with standard RADIUS clients compliant with RFC 2865. A single deployment can simultaneously serve FortiGate, Cisco ASA/FTD, Palo Alto GlobalProtect, SonicWall, and other RADIUS-authenticated services. Users enroll once and their token works across all gateways. See RADIUS authentication with MFA and MFA for VPN for the broader architecture.

Start Securing FortiGate Today

FortiGate is a high-value target. The SSL VPN vulnerability history and the documented credential-based campaigns of 2024–2026 make password-only VPN authentication an accepted risk that’s difficult to justify to auditors, insurers, or incident response teams after the fact.

Protectimus adds MFA to FortiGate in one day without replacing your gateway, without FortiToken per-user licenses, and without FortiAuthenticator.

Start for free — up to 10 users plus $25 in testing credit. No credit card required.

Send Us A Message icon

Отправьте нам сообщение

    Этот сайт зарегистрирован на wpml.org как сайт разработки. Переключитесь на рабочий сайт по ключу remove this banner.