{"id":18346,"date":"2026-07-23T18:49:38","date_gmt":"2026-07-23T18:49:38","guid":{"rendered":"https:\/\/www.protectimus.com\/?page_id=18346"},"modified":"2026-07-29T13:47:39","modified_gmt":"2026-07-29T13:47:39","slug":"mfa-for-fortigate","status":"publish","type":"page","link":"https:\/\/www.protectimus.com\/uk\/mfa-for-fortigate\/","title":{"rendered":"MFA for FortiGate: Two-Factor Authentication Without FortiToken Pricing"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-page\" data-elementor-id=\"18346\" class=\"elementor elementor-18346\" data-elementor-post-type=\"page\">\n\t\t\t\t<div class=\"elementor-element elementor-element-223acb9 padded e-flex e-con-boxed e-con e-parent\" data-id=\"223acb9\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-e4740cc elementor-widget elementor-widget-heading\" data-id=\"e4740cc\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h1 class=\"elementor-heading-title elementor-size-default\">MFA for FortiGate: Two-Factor Authentication Without FortiToken Pricing<\/h1>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-b4a66c0 e-con-full e-flex e-con e-child\" data-id=\"b4a66c0\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-0870f66 e-con-full e-flex e-con e-child\" data-id=\"0870f66\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-e128a97 elementor-widget elementor-widget-text-editor\" data-id=\"e128a97\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">FortiGate is the most widely deployed next-generation firewall in the enterprise market \u2014 and for the last four years, it has also been one of the most consistently targeted. The SSL VPN interface, the management console, and the FortiOS core have each produced critical vulnerabilities that attackers have exploited within days of disclosure, sometimes before patches were even available.<\/span><\/p><p><span style=\"font-weight: 400;\">Passwords alone do not protect a FortiGate VPN. The credential attacks documented against Fortinet devices in 2024\u20132026 didn&#8217;t require vulnerability exploitation \u2014 they used valid usernames and passwords obtained from phishing, credential stuffing, or configuration file leaks from previously compromised devices.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-20c72f6 elementor-widget elementor-widget-html\" data-id=\"20c72f6\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"html.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<script type=\"application\/ld+json\">\r\n\r\n{\r\n\r\n  \"@context\": \"https:\/\/schema.org\",\r\n\r\n  \"@type\": \"BreadcrumbList\",\r\n\r\n  \"itemListElement\": [\r\n\r\n    {\"@type\": \"ListItem\", \"position\": 1, \"name\": \"Home\", \"item\": \"https:\/\/protectimus.com\/\"},\r\n\r\n    {\"@type\": \"ListItem\", \"position\": 2, \"name\": \"Solutions\", \"item\": \"https:\/\/protectimus.com\/solutions\/\"},\r\n\r\n    {\"@type\": \"ListItem\", \"position\": 3, \"name\": \"MFA for FortiGate\", \"item\": \"https:\/\/protectimus.com\/mfa-for-fortigate\/\"}\r\n\r\n  ]\r\n\r\n}\r\n\r\n<\/script>\r\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-42bfc14 e-con-full e-flex e-con e-child\" data-id=\"42bfc14\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-6818e9e elementor-widget elementor-widget-heading\" data-id=\"6818e9e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Table of Contents<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-282e74f elementor-widget elementor-widget-text-editor\" data-id=\"282e74f\" data-element_type=\"widget\" data-e-type=\"widget\" id=\"why-on-premise-mfa-matters-2026\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<ol><li><a href=\"#why-fortigate-vpn-needs-mfa\"><span style=\"font-weight: 400;\">Why FortiGate VPN Needs MFA Beyond Passwords<\/span><\/a><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"#fortitoken-vs-third-party-mfa\"><span style=\"font-weight: 400;\">FortiToken vs Third-Party MFA: The Real Cost<\/span><\/a><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"#how-protectimus-mfa-works\"><span style=\"font-weight: 400;\">How Protectimus MFA Works with FortiGate<\/span><\/a><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"#what-you-can-protect\"><span style=\"font-weight: 400;\">What You Can Protect<\/span><\/a><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"#supported-authentication-methods\"><span style=\"font-weight: 400;\">Supported Authentication Methods<\/span><\/a><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"#step-by-step-fortigate-mfa\"><span style=\"font-weight: 400;\">Step-by-Step: FortiGate MFA in 4 Steps<\/span><\/a><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"#compliance\"><span style=\"font-weight: 400;\">Compliance<\/span><\/a><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"#faq\"><span style=\"font-weight: 400;\">FAQ<\/span><\/a><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"#start-securing-fortigate\"><span style=\"font-weight: 400;\">Start Securing FortiGate Today<\/span><\/a><\/li><\/ol>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-b904199 padded e-flex e-con-boxed e-con e-parent\" data-id=\"b904199\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-1b1c9bb e-con-full e-flex e-con e-child\" data-id=\"1b1c9bb\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-f07f411 elementor-widget elementor-widget-heading\" data-id=\"f07f411\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Quick Answer<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-54d9acf elementor-widget elementor-widget-text-editor\" data-id=\"54d9acf\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>\u00a0Protectimus adds MFA to FortiGate SSL VPN, IPsec VPN, and admin access through a Protectimus RADIUS Server \u2014 TOTP apps and hardware tokens, SMS, chatbots, and email OTP, no FortiToken per-user licenses required. Standard single-gateway deployment completes in one day.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-cdef92e padded e-flex e-con-boxed e-con e-parent\" data-id=\"cdef92e\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-56c84d1 elementor-widget elementor-widget-heading\" data-id=\"56c84d1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Key facts\n<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-bff780b elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"bff780b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-d391a8f e-grid e-con-boxed e-con e-child\" data-id=\"d391a8f\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-64a96a2 border-left e-flex e-con-boxed e-con e-child\" data-id=\"64a96a2\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-4dfef98 elementor-widget elementor-widget-heading\" data-id=\"4dfef98\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">MFA blocks over 99.2% of automated credential attacks<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-0cc1bea elementor-widget elementor-widget-heading\" data-id=\"0cc1bea\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-heading-title elementor-size-default\">Microsoft<\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f5e29e2 elementor-widget elementor-widget-text-editor\" data-id=\"f5e29e2\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Microsoft&#8217;s Digital Defense Report 2025 found that MFA remains the single highest-impact control against credential-based intrusions \u2014 the attack type that most directly targets FortiGate VPN endpoints.<\/span><span style=\"font-weight: 400;\"> (<\/span><a target=\"_blank\" target=\"_blank\" href=\"https:\/\/www.microsoft.com\/en-us\/corporate-responsibility\/cybersecurity\/microsoft-digital-defense-report-2025\/\"><span style=\"font-weight: 400;\">Microsoft Digital Defense Report<\/span><\/a><span style=\"font-weight: 400;\">)<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-f5947b8 border-left e-flex e-con-boxed e-con e-child\" data-id=\"f5947b8\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-fa74c1f elementor-hidden-desktop elementor-hidden-tablet elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"fa74c1f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-47e43b7 elementor-widget elementor-widget-heading\" data-id=\"47e43b7\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">26 Fortinet CVEs in the CISA Known Exploited Vulnerabilities catalog<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-fb629a4 elementor-widget elementor-widget-heading\" data-id=\"fb629a4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-heading-title elementor-size-default\">CISA<\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-8085769 elementor-widget elementor-widget-text-editor\" data-id=\"8085769\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">As of July 2026, CISA has confirmed 26 Fortinet vulnerabilities actively exploited in the wild \u2014 more than any other network security vendor in the catalog. The most recent, CVE-2025-59718 (CVSS 9.1), allowed unauthenticated attackers to bypass FortiCloud SSO entirely via crafted SAML messages. CISA issued a 7-day patch deadline upon adding it to the KEV. \u00a0(<a target=\"_blank\" target=\"_blank\" href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?search_api_fulltext=fortinet\">CISA Known Exploited Vulnerabilities Catalog, July 2026<\/a>)<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-c6c866e elementor-hidden-desktop elementor-hidden-tablet elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"c6c866e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-5c0d1fa border-left e-flex e-con-boxed e-con e-child\" data-id=\"5c0d1fa\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-d45db87 elementor-widget elementor-widget-heading\" data-id=\"d45db87\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">FortiGate SSL VPN: the most exploited perimeter device of 2024\u20132025<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-344d455 elementor-widget elementor-widget-heading\" data-id=\"344d455\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-heading-title elementor-size-default\">Fortinet<\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3a4d317 elementor-widget elementor-widget-text-editor\" data-id=\"3a4d317\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">CVE-2022-42475, CVE-2023-27997, and CVE-2024-21762 \u2014 all FortiOS SSL VPN vulnerabilities \u2014 were chained in a multi-year persistence campaign where attackers maintained read-only access to device configurations even after patches were applied. Threat actor Mora_001 (linked to LockBit) exploited CVE-2024-55591 and CVE-2025-24472 to gain super-admin privileges on internet-exposed FortiGate devices and deploy ransomware. (Fortinet PSIRT advisory, April 2025; CISA Alert, April 2025; Forescout Vedere Labs, 2025)<br \/><\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-0ae1e9a padded e-flex e-con-boxed e-con e-parent\" data-id=\"0ae1e9a\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-e899921 elementor-widget elementor-widget-heading\" data-id=\"e899921\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Key Takeaways<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-86d1b8b elementor-widget elementor-widget-spacer\" data-id=\"86d1b8b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"spacer.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-spacer\">\n\t\t\t<div class=\"elementor-spacer-inner\"><\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-9d5e935 e-grid e-con-full e-con e-child\" data-id=\"9d5e935\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-12e9470 e-con-full e-flex e-con e-child\" data-id=\"12e9470\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-8644d62 elementor-widget elementor-widget-image\" data-id=\"8644d62\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" width=\"64\" height=\"64\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2025\/03\/key-5.svg\" class=\"attachment-full size-full wp-image-12236\" alt=\"On-Premise MFA Platform \u2013 Security feature: A Cluster-Based, Fault-Tolerant System\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-317cba7 elementor-widget elementor-widget-heading\" data-id=\"317cba7\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">One MFA server for your entire network stack<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d96a026 elementor-widget elementor-widget-text-editor\" data-id=\"d96a026\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The same Protectimus RADIUS deployment can protect FortiGate alongside Cisco, Palo Alto, SonicWall, Check Point, Juniper, F5, Citrix ADC, and other RADIUS-enabled systems<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-68b5ae8 e-con-full e-flex e-con e-child\" data-id=\"68b5ae8\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-8b57400 elementor-widget elementor-widget-image\" data-id=\"8b57400\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" width=\"56\" height=\"60\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2026\/05\/radius1.svg\" class=\"attachment-full size-full wp-image-16522\" alt=\"RADIUS MFA icon\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-767e2aa elementor-widget elementor-widget-heading\" data-id=\"767e2aa\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">RADIUS integration, no FortiToken licenses<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d73153e elementor-widget elementor-widget-text-editor\" data-id=\"d73153e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Protectimus connects to FortiGate as a standard RADIUS server; no per-user FortiToken licenses, no FortiAuthenticator appliance required.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-9d3b5b8 e-con-full e-flex e-con e-child\" data-id=\"9d3b5b8\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-89d54f8 elementor-widget elementor-widget-image\" data-id=\"89d54f8\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" width=\"57\" height=\"57\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2026\/05\/vpn2.svg\" class=\"attachment-full size-full wp-image-16525\" alt=\"VPN MFA icon\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f7f585d elementor-widget elementor-widget-heading\" data-id=\"f7f585d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">SSL VPN, IPsec VPN, and admin login<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-aff0db8 elementor-widget elementor-widget-text-editor\" data-id=\"aff0db8\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>All three FortiGate access paths covered from a single deployment.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-9ddacc7 e-con-full e-flex e-con e-child\" data-id=\"9ddacc7\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-82d1654 elementor-widget elementor-widget-image\" data-id=\"82d1654\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"56\" height=\"56\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/03\/icon-shield-56.svg\" class=\"attachment-full size-full wp-image-1756\" alt=\"On-Prem MFA Platform icon\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-eb78c60 elementor-widget elementor-widget-heading\" data-id=\"eb78c60\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Hardware OTP token support<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-ee318b2 elementor-widget elementor-widget-text-editor\" data-id=\"ee318b2\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Including programmable NFC tokens as a direct alternative to FortiToken 200.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-cb9fab9 e-con-full e-flex e-con e-child\" data-id=\"cb9fab9\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-1b3c387 elementor-widget elementor-widget-image\" data-id=\"1b3c387\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"57\" height=\"56\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2026\/05\/plat_new.svg\" class=\"attachment-full size-full wp-image-16519\" alt=\"On-premise MFA platform icon\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-84c6048 elementor-widget elementor-widget-heading\" data-id=\"84c6048\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">On-premises or cloud<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1abcc56 elementor-widget elementor-widget-text-editor\" data-id=\"1abcc56\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Deploy the Protectimus server inside your network perimeter or use the cloud service.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-7c15682 e-con-full e-flex e-con e-child\" data-id=\"7c15682\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-ffb514c elementor-widget elementor-widget-image\" data-id=\"ffb514c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"56\" height=\"56\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/icon-check.svg\" class=\"attachment-full size-full wp-image-637\" alt=\"Customer Stories section icon \u2013 real-life client experiences\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3382fca elementor-widget elementor-widget-heading\" data-id=\"3382fca\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Works with FortiClient<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-785b26a elementor-widget elementor-widget-text-editor\" data-id=\"785b26a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Standard FortiClient authentication flow, no client-side changes.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-30a9584 elementor-widget elementor-widget-spacer\" data-id=\"30a9584\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"spacer.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-spacer\">\n\t\t\t<div class=\"elementor-spacer-inner\"><\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-5b50e5c padded e-flex e-con-boxed e-con e-parent\" data-id=\"5b50e5c\" data-element_type=\"container\" data-e-type=\"container\" id=\"why-fortigate-vpn-needs-mfa\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-28b1e56 e-con-full e-flex e-con e-child\" data-id=\"28b1e56\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-a6f90e4 elementor-widget elementor-widget-heading\" data-id=\"a6f90e4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Why FortiGate VPN Needs MFA Beyond Passwords<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-9d2498b elementor-widget elementor-widget-text-editor\" data-id=\"9d2498b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">FortiGate&#8217;s SSL VPN interface has produced more critical, actively exploited vulnerabilities than almost any other enterprise security product in recent years. CVE-2018-13379 leaked VPN credentials for approximately 50,000 devices. CVE-2022-42475, CVE-2023-27997, and CVE-2024-21762 enabled remote code execution via the SSL VPN daemon with no authentication required. CVE-2024-55591 and CVE-2025-24472 granted super-admin privileges through the management WebSocket interface.<\/span><\/p><p><span style=\"font-weight: 400;\">The April 2025 Fortinet advisory described the outcome of this vulnerability chain directly: attackers created a symbolic link between the SSL VPN user file system and the root file system, maintaining read-only access to device configurations \u2014 including credentials \u2014 even after the original vulnerabilities were patched. Organizations that patched promptly were still exposed to ongoing credential harvesting from their own devices.<\/span><\/p><p><span style=\"font-weight: 400;\">Amazon Threat Intelligence documented a separate campaign in early 2026: a financially motivated threat actor using commercial AI tools to systematically compromise over 600 FortiGate devices across 55 countries. The initial access vector was credential-based \u2014 not exploitation \u2014 targeting management interfaces exposed to the internet.<\/span><\/p><p><span style=\"font-weight: 400;\">Vulnerability patching and credential hygiene are necessary but not sufficient. An attacker with a valid username and password \u2014 from a phishing campaign, a credential list, or a leaked configuration file \u2014 bypasses every defense that depends on patched vulnerabilities. MFA enforced at the authentication layer means that a stolen password alone cannot open a VPN session.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-d459193 padded e-flex e-con-boxed e-con e-parent\" data-id=\"d459193\" data-element_type=\"container\" data-e-type=\"container\" id=\"fortitoken-vs-third-party-mfa\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-9628165 e-con-full e-flex e-con e-child\" data-id=\"9628165\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-5c8f824 elementor-widget elementor-widget-heading\" data-id=\"5c8f824\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">FortiToken vs Third-Party MFA: The Real Cost<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-de0ea10 elementor-widget elementor-widget-text-editor\" data-id=\"de0ea10\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Fortinet&#8217;s native MFA products \u2014 FortiToken Mobile, FortiToken 200 hardware, and FortiAuthenticator \u2014 are purpose-built for the FortiGate ecosystem and work without a separate RADIUS server. But their licensing model creates real operational constraints.<\/span><\/p><p><b>FortiToken Mobile<\/b><span style=\"font-weight: 400;\"> requires a perpetual per-user license registered to a specific FortiGate appliance. Licenses are non-transferable between devices (for licenses issued after August 2025). If you have multiple FortiGate units across locations, you need separate license pools per appliance unless you centralize through FortiAuthenticator.<\/span><\/p><p><b>FortiToken 200<\/b><span style=\"font-weight: 400;\"> (hardware token) is a physical OATH TOTP device, also licensed per unit and tied to a specific appliance. Replacing lost tokens means purchasing new licenses. Seed files are encrypted and available only through Fortinet customer support.<\/span><\/p><p><b>FortiAuthenticator<\/b><span style=\"font-weight: 400;\"> is a separate appliance (physical or virtual) that centralizes token management across multiple FortiGate units. It resolves the per-appliance license problem but adds deployment complexity, licensing cost, and another piece of infrastructure to maintain and patch.<\/span><\/p><p><span style=\"font-weight: 400;\">The structural difference with a third-party RADIUS proxy approach:<\/span><\/p><p>\u00a0<\/p><table><thead><tr><th><p><b>Factor<\/b><\/p><\/th><th><p><b>FortiToken Mobile<\/b><\/p><\/th><th><p><b>FortiToken 200<\/b><\/p><\/th><th><p><b>Protectimus (RADIUS proxy)<\/b><\/p><\/th><\/tr><\/thead><tbody><tr><td><p><span style=\"font-weight: 400;\">License model<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Perpetual per-user, per-appliance<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Perpetual per-unit, per-appliance<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Subscription per-user, appliance-independent<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">License transfer<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Not allowed (post Aug 2025)<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Not allowed<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Not applicable<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Multi-appliance support<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Requires FortiAuthenticator<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Requires FortiAuthenticator<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Native \u2014 one server, multiple gateways<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Supported authentication methods<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">FortiToken Mobile (TOTP), FortiToken 200<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">FortiToken 200<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">TOTP apps, SMS, email, chatbots, and OATH-compliant hardware tokens (TOTP, HOTP, and OCRA)<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Programmable tokens<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">No<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">No<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Yes (Slim NFC and Flex)<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Covers non-Fortinet devices<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">No<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">No<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Yes \u2014 Cisco, Palo Alto, etc.<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Additional MFA server needed<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">No (for single appliance)<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">No (for single appliance)<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Yes (Protectimus server)<\/span><\/p><\/td><\/tr><\/tbody><\/table><p>\u00a0<\/p><p>The trade-off is straightforward: FortiToken is simpler for a single FortiGate deployment with a stable user population. Protectimus becomes more cost-effective when you have multiple FortiGate gateways, heterogeneous network infrastructure, broader authentication requirements (SMS, email, chatbots, or OATH hardware tokens), or need to protect non-Fortinet systems with the same MFA deployment.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-86abc7e padded e-flex e-con-boxed e-con e-parent\" data-id=\"86abc7e\" data-element_type=\"container\" data-e-type=\"container\" id=\"how-protectimus-mfa-works\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-f0f2e30 e-con-full e-flex e-con e-child\" data-id=\"f0f2e30\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-684bcff elementor-widget elementor-widget-heading\" data-id=\"684bcff\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">How Protectimus MFA Works with FortiGate<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-4b52e3d elementor-widget elementor-widget-text-editor\" data-id=\"4b52e3d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Protectimus integrates with FortiGate as a standard RADIUS authentication server. FortiGate communicates with Protectimus as with any standard RADIUS server. It sends authentication requests exactly as it would to any other RADIUS server.<\/p>\n<br>\n<h3>Authentication flow<\/h3>\n<div style=\"max-width: 620px; margin: 30px 0; font-family: Arial, sans-serif;\">\n  <div>\n\n    <div style=\"width: 460px; box-sizing: border-box; padding: 16px 20px; border: 1px solid #111111; background: linear-gradient(135deg, rgba(123,225,255,.35) 0%, rgba(123,225,255,.18) 45%, rgba(123,225,255,0) 100%); text-align: center;\">\n      <strong>User<\/strong><br>\n      <small>FortiClient \/ Browser<\/small>\n    <\/div>\n\n    <div style=\"width: 460px; text-align: center; margin: 8px 0;\">\n      <small style=\"color: #666;\">Enters username and password<\/small>\n      <div style=\"width: 2px; height: 18px; background: #111; margin: 4px auto 0;\"><\/div>\n      <div style=\"font-size: 13px; line-height: 10px;\">\u25bc<\/div>\n    <\/div>\n\n    <div style=\"width: 460px; box-sizing: border-box; padding: 16px 20px; border: 1px solid #111111; background: linear-gradient(135deg, rgba(123,225,255,.35) 0%, rgba(123,225,255,.18) 45%, rgba(123,225,255,0) 100%); text-align: center;\">\n      <strong>FortiGate<\/strong><br>\n      <small>SSL VPN \/ IPsec VPN \/ Admin Login<\/small>\n    <\/div>\n\n    <div style=\"width: 460px; text-align: center; margin: 8px 0;\">\n      <small style=\"color: #666;\">RADIUS Access-Request (username + password)<\/small>\n      <div style=\"width: 2px; height: 18px; background: #111; margin: 4px auto 0;\"><\/div>\n      <div style=\"font-size: 13px; line-height: 10px;\">\u25bc<\/div>\n    <\/div>\n\n    <div style=\"width: 460px; box-sizing: border-box; padding: 16px 20px; border: 1px solid #111111; background: linear-gradient(135deg, rgba(123,225,255,.35) 0%, rgba(123,225,255,.18) 45%, rgba(123,225,255,0) 100%); text-align: center;\">\n      <strong>Protectimus RADIUS Server<\/strong>\n    <\/div>\n\n    <div style=\"width: 460px; text-align: center; margin: 8px 0;\">\n      <div style=\"width: 2px; height: 18px; background: #111; margin: 0 auto;\"><\/div>\n      <div style=\"font-size: 13px; line-height: 10px;\">\u25bc<\/div>\n    <\/div>\n\n    <div style=\"width: 460px; box-sizing: border-box; padding: 16px 20px; border: 1px solid #111111; background: linear-gradient(135deg, rgba(123,225,255,.35) 0%, rgba(123,225,255,.18) 45%, rgba(123,225,255,0) 100%); text-align: center;\">\n      <strong>Protectimus Cloud Service<\/strong><br>\n      <small>or Protectimus On-Premise Platform<\/small><br><br>\n      <small>Validates credentials via AD, LDAP, or another configured authentication provider<\/small>\n    <\/div>\n\n    <div style=\"width: 460px; text-align: center; margin: 8px 0;\">\n      <small style=\"color: #666;\">Password valid \u2014 RADIUS Access-Challenge returned<\/small>\n      <div style=\"width: 2px; height: 18px; background: #111; margin: 4px auto 0;\"><\/div>\n      <div style=\"font-size: 13px; line-height: 10px;\">\u25bc<\/div>\n    <\/div>\n\n    <div style=\"width: 460px; box-sizing: border-box; padding: 16px 20px; border: 1px solid #111111; background: linear-gradient(135deg, rgba(123,225,255,.35) 0%, rgba(123,225,255,.18) 45%, rgba(123,225,255,0) 100%); text-align: center;\">\n      <strong>FortiGate<\/strong><br>\n      <small>Prompts the user for an OTP<\/small>\n    <\/div>\n\n    <div style=\"width: 460px; text-align: center; margin: 8px 0;\">\n      <small style=\"color: #666;\">OTP prompt is displayed<\/small>\n      <div style=\"width: 2px; height: 18px; background: #111; margin: 4px auto 0;\"><\/div>\n      <div style=\"font-size: 13px; line-height: 10px;\">\u25bc<\/div>\n    <\/div>\n\n    <div style=\"width: 460px; box-sizing: border-box; padding: 16px 20px; border: 1px solid #111111; background: linear-gradient(135deg, rgba(123,225,255,.35) 0%, rgba(123,225,255,.18) 45%, rgba(123,225,255,0) 100%); text-align: center;\">\n      <strong>User<\/strong><br>\n      <small>Enters a one-time password<\/small>\n    <\/div>\n\n    <div style=\"width: 460px; text-align: center; margin: 8px 0;\">\n      <small style=\"color: #666;\">RADIUS Access-Request (OTP)<\/small>\n      <div style=\"width: 2px; height: 18px; background: #111; margin: 4px auto 0;\"><\/div>\n      <div style=\"font-size: 13px; line-height: 10px;\">\u25bc<\/div>\n    <\/div>\n\n    <div style=\"width: 460px; box-sizing: border-box; padding: 16px 20px; border: 1px solid #111111; background: linear-gradient(135deg, rgba(123,225,255,.35) 0%, rgba(123,225,255,.18) 45%, rgba(123,225,255,0) 100%); text-align: center;\">\n      <strong>Protectimus RADIUS Server<\/strong>\n    <\/div>\n\n    <div style=\"width: 460px; text-align: center; margin: 8px 0;\">\n      <div style=\"width: 2px; height: 18px; background: #111; margin: 0 auto;\"><\/div>\n      <div style=\"font-size: 13px; line-height: 10px;\">\u25bc<\/div>\n    <\/div>\n\n    <div style=\"width: 460px; box-sizing: border-box; padding: 16px 20px; border: 1px solid #111111; background: linear-gradient(135deg, rgba(123,225,255,.35) 0%, rgba(123,225,255,.18) 45%, rgba(123,225,255,0) 100%); text-align: center;\">\n      <strong>Protectimus Cloud Service<\/strong><br>\n      <small>or Protectimus On-Premise Platform<\/small><br><br>\n      <small>Validates the OTP<\/small><br><br>\n      <small><strong>Returns RADIUS Access-Accept<\/strong><\/small>\n    <\/div>\n\n    <div style=\"width: 460px; text-align: center; margin: 8px 0;\">\n      <small style=\"color: #666;\">RADIUS Access-Accept returned to FortiGate<\/small>\n      <div style=\"width: 2px; height: 18px; background: #111; margin: 4px auto 0;\"><\/div>\n      <div style=\"font-size: 13px; line-height: 10px;\">\u25bc<\/div>\n    <\/div>\n\n    <div style=\"width: 460px; box-sizing: border-box; padding: 16px 20px; border: 1px solid #111111; background: linear-gradient(135deg, rgba(123,225,255,.60) 0%, rgba(123,225,255,.38) 45%, rgba(123,225,255,.08) 100%); text-align: center;\">\n      <strong>FortiGate<\/strong><br>\n      <small>Establishes the VPN or administrator session<\/small>\n    <\/div>\n\n  <\/div>\n<\/div>\n<br>\n\n<h3>FortiGate configuration overview<\/h3>\n<p>On the FortiGate side, the configuration involves three components:<\/p>\n\n<p><b>RADIUS server definition.<\/b> Add Protectimus as a RADIUS server under User &amp; Authentication \u2192 RADIUS Servers. Set the server IP, shared secret, and authentication method (PAP). Increase the server timeout to at least 30 seconds \u2014 the default 5-second timeout causes authentication failures when users take longer than that to retrieve their OTP.<\/p>\n\n<p><b>User group.<\/b> Create or modify a user group that references the Protectimus RADIUS server as the remote authentication source. SSL VPN policies and admin profiles will reference this group.<\/p>\n\n<p><b>SSL VPN \/ firewall policy assignment.<\/b> Assign the RADIUS-authenticated user group to the relevant SSL VPN portal and firewall policies.<\/p>\n\n<p>For the complete configuration with CLI commands and screenshots, see the <a href=\"https:\/\/www.protectimus.com\/uk\/guides\/fortigate-vpn-2fa\/\">full FortiGate 2FA setup guide<\/a>.<\/p>\n<br>\n<h3>Access-Challenge and Inline Mode<\/h3>\n<p>FortiGate supports RADIUS Access-Challenge in its SSL VPN web portal and tunnel mode clients. When the Access-Challenge is issued, FortiClient presents a secondary OTP input field to the user after the password is accepted.<\/p>\n\n<p>For configurations where challenge\/response creates issues \u2014 certain FortiClient versions or IPsec authentication paths \u2014 Protectimus supports <b>Inline Mode<\/b>: the user enters password and OTP in a single field with a configured separator (for example, MyPassword,123456). The Protectimus server parses the combined input and validates each component separately.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-280411b padded e-flex e-con-boxed e-con e-parent\" data-id=\"280411b\" data-element_type=\"container\" data-e-type=\"container\" id=\"what-you-can-protect\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-2bd5d59 e-con-full e-flex e-con e-child\" data-id=\"2bd5d59\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-347cae5 elementor-widget elementor-widget-heading\" data-id=\"347cae5\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">What You Can Protect<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3977085 elementor-widget elementor-widget-text-editor\" data-id=\"3977085\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">A single Protectimus RADIUS deployment covers all FortiGate authentication surfaces:<\/span><\/p><p><b>SSL VPN<\/b><span style=\"font-weight: 400;\"> \u2014 the primary remote access path. Both web portal (browser-based) and tunnel mode (FortiClient) authentication go through the RADIUS server. This is the highest-risk surface given the SSL VPN vulnerability history.<\/span><\/p><p><b>IPsec VPN<\/b><span style=\"font-weight: 400;\"> \u2014 site-to-site and client-to-site IPsec configurations that use XAUTH or IKEv1\/IKEv2 with RADIUS authentication. IPsec deployments that rely only on a pre-shared key don&#8217;t require user authentication, but configurations using XAuth or EAP with RADIUS can authenticate users through Protectimus. This covers remote workers using FortiClient with IPsec tunnel mode as an alternative to SSL VPN.<\/span><\/p><p><b>FortiGate admin login<\/b><span style=\"font-weight: 400;\"> \u2014 the management GUI (HTTPS) and SSH administrative access. FortiOS supports RADIUS authentication for admin accounts, allowing the same MFA enforcement on administrative sessions that applies to VPN users. Admin accounts represent the highest-value target \u2014 super-admin access gives complete control over firewall rules, VPN configuration, and logging.<\/span><\/p><p><b>FortiClient EMS deployments<\/b><span style=\"font-weight: 400;\"> \u2014 FortiClient EMS-managed VPN deployments can use the same Protectimus RADIUS server for authentication.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-a29b829 padded e-flex e-con-boxed e-con e-parent\" data-id=\"a29b829\" data-element_type=\"container\" data-e-type=\"container\" id=\"supported-authentication-methods\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-1dc9ec2 e-con-full e-flex e-con e-child\" data-id=\"1dc9ec2\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-131348d elementor-widget elementor-widget-heading\" data-id=\"131348d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Supported Authentication Methods<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-5266633 elementor-widget elementor-widget-text-editor\" data-id=\"5266633\" data-element_type=\"widget\" data-e-type=\"widget\" id=\"supported-mfa-methods\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<table><thead><tr><th><p><b>Method<\/b><\/p><\/th><th><p><b>Delivery<\/b><\/p><\/th><th><p><b>Best for<\/b><\/p><\/th><\/tr><\/thead><tbody><tr><td><p><a href=\"https:\/\/www.protectimus.com\/uk\/token\/smart\/\"><b>TOTP via Protectimus SMART app<\/b><\/a><\/p><\/td><td><p><span style=\"font-weight: 400;\">Authenticator app, 30-second codes<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Most enterprise users with smartphones<\/span><\/p><\/td><\/tr><tr><td><p><a href=\"https:\/\/www.protectimus.com\/uk\/token\/slim\/\"><b>Slim NFC hardware token<\/b><\/a><\/p><\/td><td><p><span style=\"font-weight: 400;\">Programmable NFC card-format token (TOTP)<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Organizations requiring reusable hardware tokens; direct alternative to FortiToken 200<\/span><\/p><\/td><\/tr><tr><td><p><a href=\"https:\/\/www.protectimus.com\/uk\/token\/flex\/\"><b>FLEX hardware token<\/b><\/a><\/p><\/td><td><p><span style=\"font-weight: 400;\">Programmable NFC key-fob hardware token (TOTP)<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Organizations requiring reusable hardware tokens; direct alternative to FortiToken 200<\/span><\/p><\/td><\/tr><tr><td><p><b><a href=\"https:\/\/www.protectimus.com\/uk\/token\/two\/\">TWO<\/a> \/ <a href=\"https:\/\/www.protectimus.com\/uk\/token\/shark\/\">SHARK<\/a> hardware tokens<\/b><\/p><\/td><td><p><span style=\"font-weight: 400;\">Classic TOTP tokens in a key-fob form factor\u00a0<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Users without smartphones; high-security roles<\/span><\/p><\/td><\/tr><tr><td><p><a href=\"https:\/\/www.protectimus.com\/uk\/token\/sms\/\"><b>SMS OTP<\/b><\/a><\/p><\/td><td><p><span style=\"font-weight: 400;\">6-digit code via SMS<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Users without smartphones or reliable Internet access<\/span><\/p><\/td><\/tr><tr><td><p><a href=\"https:\/\/www.protectimus.com\/uk\/token\/mail\/\"><b>Email OTP<\/b><\/a><\/p><\/td><td><p><span style=\"font-weight: 400;\">6-digit code via email<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Organizations that prefer email-based OTP delivery<\/span><\/p><\/td><\/tr><tr><td><p><a href=\"https:\/\/www.protectimus.com\/uk\/token\/bot\/\"><b>Chatbot OTP<\/b><\/a><\/p><\/td><td><p><span style=\"font-weight: 400;\">OTP via Telegram, Viber or Facebook Messenger<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Organizations looking for a convenient, low-cost alternative to SMS OTP<\/span><\/p><\/td><\/tr><\/tbody><\/table><p>\u00a0<\/p><p><b>Note on hardware tokens:<\/b><span style=\"font-weight: 400;\"> The Protectimus Slim NFC and Protectimus FLEX are programmable OATH TOTP tokens \u2014 the closest functional equivalents to the FortiToken 200, but with a key difference: the seed can be reprogrammed. When a user leaves the organization, the token can be reassigned and re-enrolled rather than replaced. Any OATH-compliant TOTP, HOTP, or OCRA hardware token also works.<\/span><\/p><p><span style=\"font-weight: 400;\">For the full <\/span><a href=\"https:\/\/www.protectimus.com\/uk\/tokens\/\"><span style=\"font-weight: 400;\">hardware TOTP tokens<\/span><\/a><span style=\"font-weight: 400;\"> portfolio, see the tokens page.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-16797b4 padded e-flex e-con-boxed e-con e-parent\" data-id=\"16797b4\" data-element_type=\"container\" data-e-type=\"container\" id=\"step-by-step-fortigate-mfa\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-bb86bc5 e-con-full e-flex e-con e-child\" data-id=\"bb86bc5\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-891beb3 elementor-widget elementor-widget-heading\" data-id=\"891beb3\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Step-by-Step: FortiGate MFA in 4 Steps<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d7f6098 elementor-widget elementor-widget-text-editor\" data-id=\"d7f6098\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><b>Step 1 \u2014 Deploy Protectimus.<\/b><span style=\"font-weight: 400;\"> Choose the Protectimus Cloud Service or On-Premise Platform. Install and configure the Protectimus RADIUS Server inside your network. For an on-premises deployment, install both the Protectimus On-Premise Platform and the Protectimus RADIUS Server, then configure Active Directory or LDAP synchronization if required. See the <\/span><a href=\"https:\/\/www.protectimus.com\/uk\/platform\/\"><span style=\"font-weight: 400;\">on-premises MFA platform<\/span><\/a><span style=\"font-weight: 400;\"> page for system requirements.<\/span><\/p><p><b>Step 2 \u2014 Add Protectimus as a RADIUS server on FortiGate.<\/b><span style=\"font-weight: 400;\"> In the FortiGate web UI:<\/span> <b>User &amp; Authentication \u2192 RADIUS Servers \u2192 Create New<\/b><span style=\"font-weight: 400;\">. Enter the Protectimus server IP, set a strong shared secret, select PAP as the authentication method, and set the timeout to 30 seconds. Test the connection to confirm RADIUS communication is working.<\/span><\/p><p><b>Step 3 \u2014 Configure user group and authentication policy.<\/b><span style=\"font-weight: 400;\"> Create a user group referencing the Protectimus RADIUS server. Assign this group to the SSL VPN portal, tunnel mode policy, or admin profile as appropriate. For admin login MFA, edit the admin account under <\/span><strong>System \u2192 Administrators<\/strong><span style=\"font-weight: 400;\"> and set the authentication to use the RADIUS-authenticated group.\u00a0<\/span><\/p><p><b>Step 4 \u2014 Enroll users and test.<\/b><span style=\"font-weight: 400;\"> Send self-enrollment links to a pilot group. Users register their authenticator app by scanning a QR code, or receive a hardware token assignment. Test the full flow: connect via SSL VPN, enter credentials, confirm the OTP prompt appears, verify successful session establishment. Then extend enrollment to the full user population.<\/span><\/p><p><span style=\"font-weight: 400;\">For CLI commands, specific FortiOS version notes, and IPsec configuration, see the <\/span><a href=\"https:\/\/www.protectimus.com\/uk\/guides\/fortigate-vpn-2fa\/\"><span style=\"font-weight: 400;\">full FortiGate 2FA setup guide<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-a2442ac padded e-flex e-con-boxed e-con e-parent\" data-id=\"a2442ac\" data-element_type=\"container\" data-e-type=\"container\" id=\"compliance\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-d2891c1 e-con-full e-flex e-con e-child\" data-id=\"d2891c1\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-f2847f8 elementor-widget elementor-widget-heading\" data-id=\"f2847f8\" data-element_type=\"widget\" data-e-type=\"widget\" id=\"howtosetup\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Compliance<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-32a2622 elementor-widget elementor-widget-text-editor\" data-id=\"32a2622\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><b>PCI DSS v4.0 (Requirements 8.4.2 and 8.4.3)<\/b><span style=\"font-weight: 400;\">\u00a0<\/span><\/p><p><span style=\"font-weight: 400;\">Requirement 8.4.3 mandates MFA for all remote access to the cardholder data environment originating from outside the organization&#8217;s network. FortiGate SSL VPN and IPsec VPN connections into environments that touch payment systems fall directly under this requirement. Requirement 8.4.2 extends MFA requirements to access into the cardholder data environment, including admin login to FortiGate devices that manage in-scope network segments.<\/span><\/p><p><b>NIST SP 800-63B (AAL2)<\/b><span style=\"font-weight: 400;\">\u00a0<\/span><\/p><p><span style=\"font-weight: 400;\">Authenticator Assurance Level 2 requires two distinct authentication factors for access to sensitive systems. TOTP via authenticator app or hardware token satisfies AAL2 \u2014 the password is the memorized secret, the token is the bound authenticator.<\/span><\/p><p><b>NIS2 Directive (Article 21)<\/b><span style=\"font-weight: 400;\">\u00a0<\/span><\/p><p><span style=\"font-weight: 400;\">Essential and important entities in EU member states must implement MFA or continuous authentication for access to network and information systems. FortiGate VPN access to internal infrastructure is explicitly in scope.<\/span><\/p><p><b>ISO\/IEC 27001:2022 (Annex A 8.5)<\/b><span style=\"font-weight: 400;\">\u00a0<\/span><\/p><p><span style=\"font-weight: 400;\">Secure authentication controls are explicitly recommended for remote access and administrative account scenarios.<\/span><\/p><p><b>Cyber insurance requirements<\/b><span style=\"font-weight: 400;\">\u00a0<\/span><\/p><p><span style=\"font-weight: 400;\">MFA on remote access \u2014 specifically VPN and RDP \u2014 has become a standard underwriting requirement for cyber liability policies. FortiGate SSL VPN without MFA is frequently flagged in pre-binding security assessments and can result in either policy denial or significantly higher premiums. Demonstrating MFA enforcement via RADIUS directly satisfies this requirement in most policy applications. Following the widely reported FortiGate exploitation campaigns of 2024\u20132025, some insurers have begun requiring documented evidence of MFA on perimeter devices as a condition of renewal, not just initial binding.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-a9cb282 padded e-flex e-con-boxed e-con e-parent\" data-id=\"a9cb282\" data-element_type=\"container\" data-e-type=\"container\" id=\"faq\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-7659ffd elementor-widget elementor-widget-heading\" data-id=\"7659ffd\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">FAQ<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-dc81e4c e-con-full padded e-flex e-con e-child\" data-id=\"dc81e4c\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-fb2596d e-con-full faq-container e-flex e-con e-child\" data-id=\"fb2596d\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-412fa06 plus-right elementor-widget elementor-widget-n-accordion\" data-id=\"412fa06\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;default_state&quot;:&quot;all_collapsed&quot;,&quot;max_items_expended&quot;:&quot;one&quot;,&quot;n_accordion_animation_duration&quot;:{&quot;unit&quot;:&quot;ms&quot;,&quot;size&quot;:400,&quot;sizes&quot;:[]}}\" data-widget_type=\"nested-accordion.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"e-n-accordion\" aria-label=\"Accordion. Open links with Enter or Space, close with Escape, and navigate with Arrow Keys\">\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-6830\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"1\" tabindex=\"0\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-6830\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><h3 class=\"e-n-accordion-item-title-text\"> Does Protectimus replace FortiToken? <\/h3><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"2\" viewBox=\"0 0 24 2\" fill=\"none\"><path d=\"M24 1L5.96046e-08 0.999999\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M12 0V24\" stroke=\"#111111\" stroke-width=\"2\"><\/path><path d=\"M24 12L5.96046e-08 12\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-6830\" class=\"elementor-element elementor-element-ea1991a e-con-full e-flex e-con e-child\" data-id=\"ea1991a\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-8bad61c elementor-widget elementor-widget-text-editor\" data-id=\"8bad61c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Yes, it replaces FortiToken as the MFA mechanism for FortiGate authentication. Users enroll in Protectimus instead of FortiToken and use a Protectimus-compatible authenticator app or hardware token. FortiToken licenses are not required.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-6831\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"2\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-6831\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><h3 class=\"e-n-accordion-item-title-text\"> Do I need FortiAuthenticator to use Protectimus with FortiGate? <\/h3><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"2\" viewBox=\"0 0 24 2\" fill=\"none\"><path d=\"M24 1L5.96046e-08 0.999999\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M12 0V24\" stroke=\"#111111\" stroke-width=\"2\"><\/path><path d=\"M24 12L5.96046e-08 12\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-6831\" class=\"elementor-element elementor-element-b2bdc68 e-con-full e-flex e-con e-child\" data-id=\"b2bdc68\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-f30747e elementor-widget elementor-widget-text-editor\" data-id=\"f30747e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">No. FortiAuthenticator is Fortinet&#8217;s centralized MFA management server \u2014 it&#8217;s commonly used to centrally manage FortiToken authentication across multiple FortiGate appliances. Protectimus functions as a RADIUS server that FortiGate talks to directly, without FortiAuthenticator in the chain.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-6832\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"3\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-6832\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><h3 class=\"e-n-accordion-item-title-text\"> Does it work with FortiClient? <\/h3><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"2\" viewBox=\"0 0 24 2\" fill=\"none\"><path d=\"M24 1L5.96046e-08 0.999999\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M12 0V24\" stroke=\"#111111\" stroke-width=\"2\"><\/path><path d=\"M24 12L5.96046e-08 12\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-6832\" class=\"elementor-element elementor-element-0787040 e-con-full e-flex e-con e-child\" data-id=\"0787040\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-9eb7aff elementor-widget elementor-widget-text-editor\" data-id=\"9eb7aff\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Yes. FortiClient uses the standard FortiGate SSL VPN authentication flow, which routes through RADIUS. FortiGate sends the RADIUS authentication request to Protectimus, which enforces MFA exactly as it does for web portal connections. No FortiClient configuration changes are required.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-6833\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"4\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-6833\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><h3 class=\"e-n-accordion-item-title-text\"> Does it cover both SSL VPN and IPsec VPN? <\/h3><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"2\" viewBox=\"0 0 24 2\" fill=\"none\"><path d=\"M24 1L5.96046e-08 0.999999\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M12 0V24\" stroke=\"#111111\" stroke-width=\"2\"><\/path><path d=\"M24 12L5.96046e-08 12\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-6833\" class=\"elementor-element elementor-element-b3373c0 e-con-full e-flex e-con e-child\" data-id=\"b3373c0\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-6ef49d2 elementor-widget elementor-widget-text-editor\" data-id=\"6ef49d2\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Yes. SSL VPN (both web portal and tunnel mode) and user-authenticated IPsec VPN configurations both support RADIUS authentication on FortiGate. A single Protectimus RADIUS server handles both.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-6834\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"5\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-6834\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><h3 class=\"e-n-accordion-item-title-text\"> Is there a hardware token option as an alternative to FortiToken 200? <\/h3><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"2\" viewBox=\"0 0 24 2\" fill=\"none\"><path d=\"M24 1L5.96046e-08 0.999999\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M12 0V24\" stroke=\"#111111\" stroke-width=\"2\"><\/path><path d=\"M24 12L5.96046e-08 12\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-6834\" class=\"elementor-element elementor-element-3e2c10e e-con-full e-flex e-con e-child\" data-id=\"3e2c10e\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-e1ee304 elementor-widget elementor-widget-text-editor\" data-id=\"e1ee304\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Yes. The Protectimus Slim NFC and Protectimus FLEX are programmable OATH TOTP tokens in card format and key-fob format \u2014 functionally equivalent to FortiToken 200 but re-programmable, which means these OTP token models can be reassigned to a new user rather than replaced when an employee leaves. Any OATH TOTP, HOTP, or OCRA-compatible hardware token also works.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-6835\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"6\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-6835\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><h3 class=\"e-n-accordion-item-title-text\"> What happens if the Protectimus MFA server goes down? <\/h3><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"2\" viewBox=\"0 0 24 2\" fill=\"none\"><path d=\"M24 1L5.96046e-08 0.999999\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M12 0V24\" stroke=\"#111111\" stroke-width=\"2\"><\/path><path d=\"M24 12L5.96046e-08 12\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-6835\" class=\"elementor-element elementor-element-67bff32 e-con-full e-flex e-con e-child\" data-id=\"67bff32\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-ed5da62 elementor-widget elementor-widget-text-editor\" data-id=\"ed5da62\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Configure a primary and secondary Protectimus RADIUS server. FortiGate&#8217;s RADIUS failover switches to the secondary server automatically if the primary doesn&#8217;t respond within the timeout. For on-premises deployments, both servers should be on different hosts in separate availability zones or physical locations.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-6836\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"7\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-6836\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><h3 class=\"e-n-accordion-item-title-text\"> Can one Protectimus server cover Cisco, Palo Alto, or SonicWall alongside FortiGate? <\/h3><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"2\" viewBox=\"0 0 24 2\" fill=\"none\"><path d=\"M24 1L5.96046e-08 0.999999\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M12 0V24\" stroke=\"#111111\" stroke-width=\"2\"><\/path><path d=\"M24 12L5.96046e-08 12\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-6836\" class=\"elementor-element elementor-element-a41023b e-con-full e-flex e-con e-child\" data-id=\"a41023b\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-2a36881 elementor-widget elementor-widget-text-editor\" data-id=\"2a36881\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Yes. Protectimus works with standard RADIUS clients compliant with RFC 2865. A single deployment can simultaneously serve FortiGate, Cisco ASA\/FTD, Palo Alto GlobalProtect, SonicWall, and other RADIUS-authenticated services. Users enroll once and their token works across all gateways. See <\/span><a href=\"https:\/\/www.protectimus.com\/uk\/radius-authentication\/\"><span style=\"font-weight: 400;\">RADIUS authentication with MFA<\/span><\/a><span style=\"font-weight: 400;\"> and <\/span><a href=\"https:\/\/www.protectimus.com\/uk\/mfa-for-vpn\/\"><span style=\"font-weight: 400;\">MFA for VPN<\/span><\/a><span style=\"font-weight: 400;\"> for the broader architecture.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t<script type=\"application\/ld+json\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"Does Protectimus replace FortiToken?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Yes, it replaces FortiToken as the MFA mechanism for FortiGate authentication. Users enroll in Protectimus instead of FortiToken and use a Protectimus-compatible authenticator app or hardware token. FortiToken licenses are not required.\"}},{\"@type\":\"Question\",\"name\":\"Do I need FortiAuthenticator to use Protectimus with FortiGate?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"No. FortiAuthenticator is Fortinet&#8217;s centralized MFA management server \\u2014 it&#8217;s commonly used to centrally manage FortiToken authentication across multiple FortiGate appliances. Protectimus functions as a RADIUS server that FortiGate talks to directly, without FortiAuthenticator in the chain.\"}},{\"@type\":\"Question\",\"name\":\"Does it work with FortiClient?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Yes. FortiClient uses the standard FortiGate SSL VPN authentication flow, which routes through RADIUS. FortiGate sends the RADIUS authentication request to Protectimus, which enforces MFA exactly as it does for web portal connections. No FortiClient configuration changes are required.\"}},{\"@type\":\"Question\",\"name\":\"Does it cover both SSL VPN and IPsec VPN?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Yes. SSL VPN (both web portal and tunnel mode) and user-authenticated IPsec VPN configurations both support RADIUS authentication on FortiGate. A single Protectimus RADIUS server handles both.\"}},{\"@type\":\"Question\",\"name\":\"Is there a hardware token option as an alternative to FortiToken 200?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Yes. The Protectimus Slim NFC and Protectimus FLEX are programmable OATH TOTP tokens in card format and key-fob format \\u2014 functionally equivalent to FortiToken 200 but re-programmable, which means these OTP token models can be reassigned to a new user rather than replaced when an employee leaves. Any OATH TOTP, HOTP, or OCRA-compatible hardware token also works.\"}},{\"@type\":\"Question\",\"name\":\"What happens if the Protectimus MFA server goes down?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Configure a primary and secondary Protectimus RADIUS server. FortiGate&#8217;s RADIUS failover switches to the secondary server automatically if the primary doesn&#8217;t respond within the timeout. For on-premises deployments, both servers should be on different hosts in separate availability zones or physical locations.\"}},{\"@type\":\"Question\",\"name\":\"Can one Protectimus server cover Cisco, Palo Alto, or SonicWall alongside FortiGate?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Yes. Protectimus works with standard RADIUS clients compliant with RFC 2865. A single deployment can simultaneously serve FortiGate, Cisco ASA\\\/FTD, Palo Alto GlobalProtect, SonicWall, and other RADIUS-authenticated services. Users enroll once and their token works across all gateways. See RADIUS authentication with MFA and MFA for VPN for the broader architecture.\"}}]}<\/script>\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7534fb4 elementor-widget elementor-widget-html\" data-id=\"7534fb4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"html.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<script type=\"application\/ld+json\">\r\n{\r\n  \"@context\": \"https:\/\/schema.org\",\r\n  \"@type\": \"HowTo\",\r\n  \"name\": \"How to Set Up MFA for Cisco AnyConnect with Protectimus\",\r\n  \"description\": \"Step-by-step setup of multi-factor authentication for Cisco AnyConnect VPN using Protectimus via RADIUS: platform setup, RADIUS Server installation and configuration, ASA\/Firepower AAA configuration, AnyConnect connection profile, and user enrollment. First authentication with MFA enforced is achievable within 2\u20134 hours for a standard single-domain deployment.\",\r\n  \"totalTime\": \"PT4H\",\r\n  \"estimatedCost\": {\r\n    \"@type\": \"MonetaryAmount\",\r\n    \"currency\": \"USD\",\r\n    \"value\": \"0\"\r\n  },\r\n  \"supply\": [\r\n    {\r\n      \"@type\": \"HowToSupply\",\r\n      \"name\": \"Cisco ASA or Firepower Threat Defense appliance with AnyConnect VPN configured\"\r\n    },\r\n    {\r\n      \"@type\": \"HowToSupply\",\r\n      \"name\": \"Active Directory, LDAP, or local user directory for primary credential validation\"\r\n    },\r\n    {\r\n      \"@type\": \"HowToSupply\",\r\n      \"name\": \"Linux or Windows server for the Protectimus RADIUS Server (or for the full On-Premise Platform)\"\r\n    },\r\n    {\r\n      \"@type\": \"HowToSupply\",\r\n      \"name\": \"Network connectivity: UDP 1812\/1813 between ASA and RADIUS Server\"\r\n    },\r\n    {\r\n      \"@type\": \"HowToSupply\",\r\n      \"name\": \"Administrative access to Cisco ASDM or Firepower Management Center (FMC)\"\r\n    }\r\n  ],\r\n  \"tool\": [\r\n    {\r\n      \"@type\": \"HowToTool\",\r\n      \"name\": \"Protectimus Cloud Service or Protectimus On-Premise Platform\"\r\n    },\r\n    {\r\n      \"@type\": \"HowToTool\",\r\n      \"name\": \"Protectimus RADIUS Server\"\r\n    },\r\n    {\r\n      \"@type\": \"HowToTool\",\r\n      \"name\": \"Cisco ASDM or Firepower Management Center (FMC)\"\r\n    },\r\n    {\r\n      \"@type\": \"HowToTool\",\r\n      \"name\": \"Protectimus SMART OTP app, hardware token (Slim NFC, TWO, FLEX, SHARK), or Protectimus BOT\"\r\n    }\r\n  ],\r\n  \"step\": [\r\n    {\r\n      \"@type\": \"HowToStep\",\r\n      \"position\": 1,\r\n      \"name\": \"Set up the Protectimus platform or cloud service\",\r\n      \"text\": \"Register at protectimus.com for the cloud service, or install the Protectimus On-Premise Platform on your infrastructure. In the platform, create a Resource representing the AnyConnect VPN integration and note your API URL, Login, and API Key \u2014 they are required for the RADIUS Server configuration.\",\r\n      \"url\": \"https:\/\/protectimus.com\/mfa-for-cisco-anyconnect\/#step-1\",\r\n      \"image\": \"https:\/\/protectimus.com\/wp-content\/uploads\/2024\/07\/1.svg\"\r\n    },\r\n    {\r\n      \"@type\": \"HowToStep\",\r\n      \"position\": 2,\r\n      \"name\": \"Install and configure the Protectimus RADIUS Server\",\r\n      \"text\": \"Install the Protectimus RADIUS Server on a Linux host (recommended) or Windows server accessible from the ASA. Edit the radius.yml configuration file with your Protectimus API credentials, RADIUS shared secret, ASA client IP, LDAP\/AD connection parameters, and listening port (UDP 1812). Start the RADIUS service and confirm it is listening. Verify firewall rules allow UDP 1812 and 1813 from the ASA to the RADIUS Server.\",\r\n      \"url\": \"https:\/\/protectimus.com\/mfa-for-cisco-anyconnect\/#step-2\",\r\n      \"image\": \"https:\/\/protectimus.com\/wp-content\/uploads\/2024\/07\/2.svg\"\r\n    },\r\n    {\r\n      \"@type\": \"HowToStep\",\r\n      \"position\": 3,\r\n      \"name\": \"Configure the Cisco ASA AAA Server Group\",\r\n      \"text\": \"In Cisco ASDM, navigate to Configuration \u2192 Remote Access VPN \u2192 AAA\/Local Users \u2192 AAA Server Groups. Add a new AAA Server Group named 'protectimus' with Protocol set to RADIUS. Set Accounting Mode to Single, Reactivation Mode to Depletion, Dead Time 10, Max Failed Attempts 3. Add the Protectimus RADIUS Server with its IP, authentication port 1816, accounting port 1815, timeout 10s, and the matching shared secret. For Cisco Firepower via FMC, the equivalent path is Objects \u2192 Object Management \u2192 RADIUS Server Group \u2192 Add Group with identical parameters.\",\r\n      \"url\": \"https:\/\/protectimus.com\/mfa-for-cisco-anyconnect\/#step-3\",\r\n      \"image\": \"https:\/\/protectimus.com\/wp-content\/uploads\/2024\/07\/3.svg\"\r\n    },\r\n    {\r\n      \"@type\": \"HowToStep\",\r\n      \"position\": 4,\r\n      \"name\": \"Configure the AnyConnect VPN connection\",\r\n      \"text\": \"In Cisco ASDM, open Wizards \u2192 VPN Wizards \u2192 AnyConnect VPN Wizard. Configure the connection profile name, VPN access interface, enable SSL and IPsec, and select or generate a device certificate. Add AnyConnect client image (.pkg) files. In the Authentication Methods step, select the 'protectimus' AAA Server Group. In the SAML Configuration step, set Authentication Method to AAA, select the protectimus AAA Server Group, leave SAML Server as None. Configure the client IP address pool and DNS settings, enable 'Exempt VPN traffic from network address translation' and 'Allow Web Launch', then review and finish.\",\r\n      \"url\": \"https:\/\/protectimus.com\/mfa-for-cisco-anyconnect\/#step-4\",\r\n      \"image\": \"https:\/\/protectimus.com\/wp-content\/uploads\/2024\/07\/4.svg\"\r\n    },\r\n    {\r\n      \"@type\": \"HowToStep\",\r\n      \"position\": 5,\r\n      \"name\": \"Enroll users and assign OTP tokens\",\r\n      \"text\": \"Add users to the Protectimus platform manually, via CSV import, or via LDAP sync with Active Directory. Assign tokens (Protectimus SMART OTP app, hardware tokens, or chatbot OTP) to users manually, or activate the Self-Service Portal so users can enroll and manage their own tokens. Run authentication tests with a pilot group before broader rollout.\",\r\n      \"url\": \"https:\/\/protectimus.com\/mfa-for-cisco-anyconnect\/#step-5\",\r\n      \"image\": \"https:\/\/protectimus.com\/wp-content\/uploads\/2024\/07\/5.svg\"\r\n    }\r\n  ]\r\n}\r\n<\/script>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-fe2c5b0 padded e-flex e-con-boxed e-con e-parent\" data-id=\"fe2c5b0\" data-element_type=\"container\" data-e-type=\"container\" id=\"start-securing-fortigate\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-e4ec716 e-con-full e-flex e-con e-child\" data-id=\"e4ec716\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-35746bf e-con-full e-flex e-con e-child\" data-id=\"35746bf\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-489bd70 e-con-full e-flex e-con e-child\" data-id=\"489bd70\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-10cf0aa elementor-widget elementor-widget-heading\" data-id=\"10cf0aa\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Start Securing FortiGate Today<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-6c0eeb4 elementor-widget elementor-widget-text-editor\" data-id=\"6c0eeb4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">FortiGate is a high-value target. The SSL VPN vulnerability history and the documented credential-based campaigns of 2024\u20132026 make password-only VPN authentication an accepted risk that&#8217;s difficult to justify to auditors, insurers, or incident response teams after the fact.<\/span><\/p><p><span style=\"font-weight: 400;\">Protectimus adds MFA to FortiGate in one day without replacing your gateway, without FortiToken per-user licenses, and without FortiAuthenticator.<\/span><\/p><p><strong>Start for free \u2014 up to 10 users plus $25 in testing credit. No credit card required.<\/strong><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><a target=\"_blank\" target=\"_blank\" href=\"https:\/\/service.protectimus.com\/register\/\"><span style=\"font-weight: 400;\">Start for free \u2192 service.protectimus.com<\/span><\/a><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/www.protectimus.com\/uk\/platform\/\"><span style=\"font-weight: 400;\">On-premises deployment \u2192 Protectimus Platform<\/span><\/a><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/www.protectimus.com\/uk\/guides\/fortigate-vpn-2fa\/\"><span style=\"font-weight: 400;\">Full configuration guide \u2192 FortiGate 2FA setup guide<\/span><\/a><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/www.protectimus.com\/uk\/tokens\/\"><span style=\"font-weight: 400;\">Hardware tokens \u2192 Protectimus tokens<\/span><\/a><\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-a3f81ec e-con-full contact-us-bg e-flex e-con e-child\" data-id=\"a3f81ec\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t<div class=\"elementor-element elementor-element-fb3d121 elementor-widget elementor-widget-shortcode\" data-id=\"fb3d121\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"shortcode.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-shortcode\">\t\t<div data-elementor-type=\"container\" data-elementor-id=\"14849\" class=\"elementor elementor-14849 elementor-3585\" data-elementor-post-type=\"elementor_library\">\n\t\t\t\t<div class=\"elementor-element elementor-element-3a82e0d1 e-con-full e-flex e-con e-child\" data-id=\"3a82e0d1\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t<div class=\"elementor-element elementor-element-b4de036 elementor-widget elementor-widget-image\" data-id=\"b4de036\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"370\" height=\"370\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/05\/contact-seal.svg\" class=\"attachment-full size-full wp-image-5869\" alt=\"Send Us A Message icon\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1bc85d61 elementor-widget elementor-widget-heading\" data-id=\"1bc85d61\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">\u041d\u0430\u0434\u0456\u0448\u043b\u0456\u0442\u044c \u043d\u0430\u043c \u043f\u043e\u0432\u0456\u0434\u043e\u043c\u043b\u0435\u043d\u043d\u044f<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-cf09046 elementor-widget elementor-widget-shortcode\" data-id=\"cf09046\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"shortcode.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-shortcode\">\n<div class=\"wpcf7 no-js\" id=\"wpcf7-f8427-o1\" lang=\"uk\" dir=\"ltr\" data-wpcf7-id=\"8427\">\n<div class=\"screen-reader-response\"><p role=\"status\" aria-live=\"polite\" aria-atomic=\"true\"><\/p> <ul><\/ul><\/div>\n<form action=\"\/uk\/wp-json\/wp\/v2\/pages\/18346#wpcf7-f8427-o1\" method=\"post\" class=\"wpcf7-form init\" aria-label=\"\u041a\u043e\u043d\u0442\u0430\u043a\u0442\u043d\u0430 \u0444\u043e\u0440\u043c\u0430\" novalidate=\"novalidate\" data-status=\"init\">\n<fieldset class=\"hidden-fields-container\"><input type=\"hidden\" name=\"_wpcf7\" value=\"8427\" \/><input type=\"hidden\" name=\"_wpcf7_version\" value=\"6.1.2\" \/><input type=\"hidden\" name=\"_wpcf7_locale\" value=\"uk\" \/><input type=\"hidden\" name=\"_wpcf7_unit_tag\" value=\"wpcf7-f8427-o1\" \/><input type=\"hidden\" name=\"_wpcf7_container_post\" value=\"0\" \/><input type=\"hidden\" name=\"_wpcf7_posted_data_hash\" value=\"\" \/>\n<\/fieldset>\n<div class=\"protectimus-form\">\n\n<div class=\"row\">\n    <div class=\"col\">\n        <span class=\"wpcf7-form-control-wrap\" data-name=\"uname\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"\u0406\u043c&#039;\u044f\" value=\"\" type=\"text\" name=\"uname\" \/><\/span>\n    <\/div>\n<\/div>\n\n<div class=\"row\">\n    <div class=\"col\">\n        <span class=\"wpcf7-form-control-wrap\" data-name=\"email\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-email wpcf7-validates-as-required wpcf7-text wpcf7-validates-as-email\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"\u0415\u043b\u0435\u043a\u0442\u0440\u043e\u043d\u043d\u0430 \u043f\u043e\u0448\u0442\u0430\" value=\"\" type=\"email\" name=\"email\" \/><\/span>\n    <\/div>\n<\/div>\n\n<div class=\"row\">\n    <div class=\"col\">\n        <span class=\"wpcf7-form-control-wrap\" data-name=\"subject\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"\u0422\u0435\u043c\u0430\" value=\"\" type=\"text\" name=\"subject\" \/><\/span>\n    <\/div>\n<\/div>\n\n<div class=\"row\">\n    <div class=\"col\">\n        <span class=\"wpcf7-form-control-wrap\" data-name=\"message\"><textarea cols=\"40\" rows=\"1\" maxlength=\"2000\" class=\"wpcf7-form-control wpcf7-textarea wpcf7-validates-as-required\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"\u041f\u043e\u0432\u0456\u0434\u043e\u043c\u043b\u0435\u043d\u043d\u044f\" name=\"message\"><\/textarea><\/span>\n    <\/div>\n<\/div>\n\n<div class=\"row\">\n    <div class=\"col mb-2\">\n        <input class=\"wpcf7-form-control wpcf7-submit has-spinner\" type=\"submit\" value=\"\u041d\u0430\u0434\u0456\u0441\u043b\u0430\u0442\u0438\" \/>\n    <\/div>\n<\/div>\n\n<\/div><div class=\"wpcf7-response-output\" aria-hidden=\"true\"><\/div>\n<\/form>\n<\/div>\n<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-311ad2c e-grid e-con-full equal-height equal-height-mob e-con e-child\" data-id=\"311ad2c\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<a target=\"_blank\" target=\"_blank\" class=\"elementor-element elementor-element-feb2bbc e-con-full four-link e-flex e-con e-child\" data-id=\"feb2bbc\" data-element_type=\"container\" data-e-type=\"container\" href=\"https:\/\/service.protectimus.com\/en\/register\">\n\t\t\t\t<div class=\"elementor-element elementor-element-f27e21b eq-height elementor-widget elementor-widget-heading\" data-id=\"f27e21b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-heading-title elementor-size-default\">Start free trial<\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-76c9612 elementor-widget elementor-widget-image\" data-id=\"76c9612\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"28\" height=\"26\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/icon-arrow-big.svg\" class=\"attachment-full size-full wp-image-455\" alt=\"Arrow icon\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/a>\n\t\t<a class=\"elementor-element elementor-element-4ccade8 e-con-full four-link e-flex e-con e-child\" data-id=\"4ccade8\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\" href=\"https:\/\/www.protectimus.com\/uk\/contact-us\/\">\n\t\t\t\t<div class=\"elementor-element elementor-element-45ea78d eq-height elementor-widget elementor-widget-heading\" data-id=\"45ea78d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-heading-title elementor-size-default\">Contact sales<\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e65f9a1 elementor-widget elementor-widget-image\" data-id=\"e65f9a1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"28\" height=\"26\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/icon-arrow-big.svg\" class=\"attachment-full size-full wp-image-455\" alt=\"Arrow icon\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/a>\n\t\t<a class=\"elementor-element elementor-element-c9d4aa4 e-con-full four-link e-flex e-con e-child\" data-id=\"c9d4aa4\" data-element_type=\"container\" data-e-type=\"container\" href=\"https:\/\/www.protectimus.com\/uk\/pricing\/\">\n\t\t\t\t<div class=\"elementor-element elementor-element-b9e4eb6 eq-height elementor-widget elementor-widget-heading\" data-id=\"b9e4eb6\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-heading-title elementor-size-default\">Pricing details<\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-120f334 elementor-widget elementor-widget-image\" data-id=\"120f334\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"28\" height=\"26\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/icon-arrow-big.svg\" class=\"attachment-full size-full wp-image-455\" alt=\"Arrow icon\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/a>\n\t\t<a class=\"elementor-element elementor-element-e82cb51 e-con-full four-link e-flex e-con e-child\" data-id=\"e82cb51\" data-element_type=\"container\" data-e-type=\"container\" href=\"https:\/\/www.protectimus.com\/uk\/guides\/saas-service\/\">\n\t\t\t\t<div class=\"elementor-element elementor-element-d33e100 eq-height elementor-widget elementor-widget-heading\" data-id=\"d33e100\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-heading-title elementor-size-default\">Integration guides<\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3de24d6 elementor-widget elementor-widget-image\" data-id=\"3de24d6\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"28\" height=\"26\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/icon-arrow-big.svg\" class=\"attachment-full size-full wp-image-455\" alt=\"Arrow icon\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>MFA for FortiGate: Two-Factor Authentication Without FortiToken Pricing FortiGate is the most widely deployed next-generation firewall in the enterprise market \u2014 and for the last four years, it has also been one of the most consistently targeted. The SSL VPN interface, the management console, and the FortiOS core have each produced critical vulnerabilities that attackers [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"footnotes":""},"class_list":["post-18346","page","type-page","status-publish","hentry"],"acf":[],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO Pro 4.9.10 - aioseo.com -->\n\t<meta name=\"description\" content=\"FortiGate MFA in 1 day. Affordable FortiToken alternative supporting TOTP, SMS, email &amp; chat via RADIUS. Cloud\/Prem.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"google-site-verification\" content=\"6gzGBVioQ9rC9iYw9El7ERlDCLpc9c0ZqgJvbvqk0t4\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.protectimus.com\/uk\/mfa-for-fortigate\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO Pro (AIOSEO) 4.9.10\" \/>\n\t\t<meta property=\"og:locale\" content=\"uk_UA\" \/>\n\t\t<meta property=\"og:site_name\" content=\"PROTECTIMUS\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"MFA for FortiGate: Two-Factor Authentication for FortiGate VPN\" \/>\n\t\t<meta property=\"og:description\" content=\"FortiGate MFA in 1 day. Affordable FortiToken alternative supporting TOTP, SMS, email &amp; chat via RADIUS. Cloud\/Prem.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.protectimus.com\/uk\/mfa-for-fortigate\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/protectimus-logo.png\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/protectimus-logo.png\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-07-23T18:49:38+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-07-29T13:47:39+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"MFA for FortiGate: Two-Factor Authentication for FortiGate VPN\" \/>\n\t\t<meta name=\"twitter:description\" content=\"FortiGate MFA in 1 day. Affordable FortiToken alternative supporting TOTP, SMS, email &amp; chat via RADIUS. Cloud\/Prem.\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/protectimus-logo.png\" \/>\n\t\t<meta name=\"twitter:label1\" content=\"\u041d\u0430\u043f\u0438\u0441\u0430\u043d\u043e\" \/>\n\t\t<meta name=\"twitter:data1\" content=\"accounts@vipertop.com\" \/>\n\t\t<meta name=\"twitter:label2\" content=\"\u041f\u0440\u0438\u0431\u043b. \u0447\u0430\u0441 \u0447\u0438\u0442\u0430\u043d\u043d\u044f\" \/>\n\t\t<meta name=\"twitter:data2\" content=\"14 \u0445\u0432\u0438\u043b\u0438\u043d\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/uk\\\/mfa-for-fortigate\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/uk\\\/#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.protectimus.com\\\/uk\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/uk\\\/mfa-for-fortigate\\\/#listItem\",\"name\":\"MFA for FortiGate: Two-Factor Authentication Without FortiToken Pricing\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/uk\\\/mfa-for-fortigate\\\/#listItem\",\"position\":2,\"name\":\"MFA for FortiGate: Two-Factor Authentication Without FortiToken Pricing\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/uk\\\/#listItem\",\"name\":\"Home\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/uk\\\/#organization\",\"name\":\"Protectimus\",\"description\":\"Two-Factor Authentication Provider\",\"url\":\"https:\\\/\\\/www.protectimus.com\\\/uk\\\/\",\"telephone\":\"+17867966664\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.protectimus.com\\\/wp-content\\\/uploads\\\/2024\\\/02\\\/logo-icon.svg\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/uk\\\/mfa-for-fortigate\\\/#organizationLogo\",\"width\":72,\"height\":51,\"caption\":\"Protectimus logo\"},\"image\":{\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/uk\\\/mfa-for-fortigate\\\/#organizationLogo\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/uk\\\/mfa-for-fortigate\\\/#webpage\",\"url\":\"https:\\\/\\\/www.protectimus.com\\\/uk\\\/mfa-for-fortigate\\\/\",\"name\":\"MFA for FortiGate: Two-Factor Authentication for FortiGate VPN\",\"description\":\"FortiGate MFA in 1 day. Affordable FortiToken alternative supporting TOTP, SMS, email & chat via RADIUS. Cloud\\\/Prem.\",\"inLanguage\":\"uk\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/uk\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/uk\\\/mfa-for-fortigate\\\/#breadcrumblist\"},\"datePublished\":\"2026-07-23T18:49:38+00:00\",\"dateModified\":\"2026-07-29T13:47:39+00:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/uk\\\/#website\",\"url\":\"https:\\\/\\\/www.protectimus.com\\\/uk\\\/\",\"name\":\"PROTECTIMUS\",\"inLanguage\":\"uk\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/uk\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO Pro -->\r\n\t\t<title>MFA for FortiGate: Two-Factor Authentication for FortiGate VPN<\/title>\n\n","aioseo_head_json":{"title":"MFA for FortiGate: Two-Factor Authentication for FortiGate VPN","description":"FortiGate MFA in 1 day. Affordable FortiToken alternative supporting TOTP, SMS, email & chat via RADIUS. Cloud\/Prem.","canonical_url":"https:\/\/www.protectimus.com\/uk\/mfa-for-fortigate\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"google-site-verification":"6gzGBVioQ9rC9iYw9El7ERlDCLpc9c0ZqgJvbvqk0t4","miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BreadcrumbList","@id":"https:\/\/www.protectimus.com\/uk\/mfa-for-fortigate\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.protectimus.com\/uk\/#listItem","position":1,"name":"Home","item":"https:\/\/www.protectimus.com\/uk\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.protectimus.com\/uk\/mfa-for-fortigate\/#listItem","name":"MFA for FortiGate: Two-Factor Authentication Without FortiToken Pricing"}},{"@type":"ListItem","@id":"https:\/\/www.protectimus.com\/uk\/mfa-for-fortigate\/#listItem","position":2,"name":"MFA for FortiGate: Two-Factor Authentication Without FortiToken Pricing","previousItem":{"@type":"ListItem","@id":"https:\/\/www.protectimus.com\/uk\/#listItem","name":"Home"}}]},{"@type":"Organization","@id":"https:\/\/www.protectimus.com\/uk\/#organization","name":"Protectimus","description":"Two-Factor Authentication Provider","url":"https:\/\/www.protectimus.com\/uk\/","telephone":"+17867966664","logo":{"@type":"ImageObject","url":"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/logo-icon.svg","@id":"https:\/\/www.protectimus.com\/uk\/mfa-for-fortigate\/#organizationLogo","width":72,"height":51,"caption":"Protectimus logo"},"image":{"@id":"https:\/\/www.protectimus.com\/uk\/mfa-for-fortigate\/#organizationLogo"}},{"@type":"WebPage","@id":"https:\/\/www.protectimus.com\/uk\/mfa-for-fortigate\/#webpage","url":"https:\/\/www.protectimus.com\/uk\/mfa-for-fortigate\/","name":"MFA for FortiGate: Two-Factor Authentication for FortiGate VPN","description":"FortiGate MFA in 1 day. Affordable FortiToken alternative supporting TOTP, SMS, email & chat via RADIUS. Cloud\/Prem.","inLanguage":"uk","isPartOf":{"@id":"https:\/\/www.protectimus.com\/uk\/#website"},"breadcrumb":{"@id":"https:\/\/www.protectimus.com\/uk\/mfa-for-fortigate\/#breadcrumblist"},"datePublished":"2026-07-23T18:49:38+00:00","dateModified":"2026-07-29T13:47:39+00:00"},{"@type":"WebSite","@id":"https:\/\/www.protectimus.com\/uk\/#website","url":"https:\/\/www.protectimus.com\/uk\/","name":"PROTECTIMUS","inLanguage":"uk","publisher":{"@id":"https:\/\/www.protectimus.com\/uk\/#organization"}}]},"og:locale":"uk_UA","og:site_name":"PROTECTIMUS","og:type":"article","og:title":"MFA for FortiGate: Two-Factor Authentication for FortiGate VPN","og:description":"FortiGate MFA in 1 day. Affordable FortiToken alternative supporting TOTP, SMS, email &amp; chat via RADIUS. Cloud\/Prem.","og:url":"https:\/\/www.protectimus.com\/uk\/mfa-for-fortigate\/","og:image":"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/protectimus-logo.png","og:image:secure_url":"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/protectimus-logo.png","article:published_time":"2026-07-23T18:49:38+00:00","article:modified_time":"2026-07-29T13:47:39+00:00","twitter:card":"summary_large_image","twitter:title":"MFA for FortiGate: Two-Factor Authentication for FortiGate VPN","twitter:description":"FortiGate MFA in 1 day. Affordable FortiToken alternative supporting TOTP, SMS, email &amp; chat via RADIUS. Cloud\/Prem.","twitter:image":"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/protectimus-logo.png","twitter:label1":"\u041d\u0430\u043f\u0438\u0441\u0430\u043d\u043e","twitter:data1":"accounts@vipertop.com","twitter:label2":"\u041f\u0440\u0438\u0431\u043b. \u0447\u0430\u0441 \u0447\u0438\u0442\u0430\u043d\u043d\u044f","twitter:data2":"14 \u0445\u0432\u0438\u043b\u0438\u043d"},"aioseo_meta_data":{"post_id":"18346","title":"MFA for FortiGate: Two-Factor Authentication for FortiGate VPN","description":"FortiGate MFA in 1 day. Affordable FortiToken alternative supporting TOTP, SMS, email &amp; chat via RADIUS. Cloud\/Prem.","keywords":null,"keyphrases":{"focus":{"keyphrase":"","score":0,"analysis":{"keyphraseInTitle":{"score":0,"maxScore":9,"error":1}}},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"WebPage","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"seo_analyzer_scan_date":"2026-07-29 14:35:04","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"open_ai":null,"ai":{"faqs":[],"keyPoints":[],"schemas":[],"titles":[],"descriptions":[],"socialPosts":{"email":[],"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"created":"2026-07-23 17:24:09","updated":"2026-07-29 14:35:04"},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.protectimus.com\/uk\/\" title=\"Home\">Home<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\tMFA for FortiGate: Two-Factor Authentication Without FortiToken Pricing\n<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.protectimus.com\/uk\/"},{"label":"MFA for FortiGate: Two-Factor Authentication Without FortiToken Pricing","link":"https:\/\/www.protectimus.com\/uk\/mfa-for-fortigate\/"}],"_links":{"self":[{"href":"https:\/\/www.protectimus.com\/uk\/wp-json\/wp\/v2\/pages\/18346","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.protectimus.com\/uk\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.protectimus.com\/uk\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.protectimus.com\/uk\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.protectimus.com\/uk\/wp-json\/wp\/v2\/comments?post=18346"}],"version-history":[{"count":13,"href":"https:\/\/www.protectimus.com\/uk\/wp-json\/wp\/v2\/pages\/18346\/revisions"}],"predecessor-version":[{"id":18511,"href":"https:\/\/www.protectimus.com\/uk\/wp-json\/wp\/v2\/pages\/18346\/revisions\/18511"}],"wp:attachment":[{"href":"https:\/\/www.protectimus.com\/uk\/wp-json\/wp\/v2\/media?parent=18346"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}