Thanks for the work around. Unfortunately we are not using RADIUS yet. So, it looks like I will need to decide between switching everyone to SSL VPNs (performance has been notably worse then IPsec in our environment) so we can continue to use mobile push or disable mobile push and force them to manually key in their token every request
I just tested it and it works. You can enable push notification in RADIUS policy (If you are using FAC as RADIUS server) and when trying to connect through IPSec VPN, you just type "push" instead of token and then you recieve push notification to mobile app and can aprove login that way.
My company has two FortiGates and there are three IT admins (including myself). I also have a couple VPN users. Right now, VPN users use mobile FortiToken for MFA and it seems to work totally fine. I am also needing to enable MFA for the FortiGate admin accounts and one thing I wanted to do is to have the token on both my phone and iPad as a backup. However I now realize that I can only use one mobile token per FortiGate and per mobile MFA device, so I would have to have one token per admin account, per device. So for 3 admins across 2 FortiGates with two devices each, that's 12 tokens.
If your mobile device supports QR code recognition, you can simply press Scan Barcode from the Fortitoken Mobile home screen and point your device's camera at the opened QR code attachment.
FortiToken Mobile can receive push notifications even when your mobile device is locked or on the home screen as well as when FortiToken Mobile app is open. You can choose to approve or deny the login request. Once action is taken on the login request, the message "Request sent successfully" displays for 1.5 seconds.
FortiToken Mobile is a secure and convenient OTP generator for mobile devices. It is an application that generates time-based one-time passwords (OTPs) in a highly secure way, which means that your secrets are safe and accessible only to you. This is possible because your secrets are stored in a secure way, protected by the application itself. The application allows you to create tokens and to install them on your mobile devices. The tokens are stored on your mobile devices and are necessary for the functioning of the application.
This application is the client component of the FortiNet solution. It is a web-based application that generates OTP tokens and it is accessible through a secure portal, from any web browser or mobile device. The solution is highly secure because the web portal is protected by a military-grade encryption.
FortiToken Mobile is an OATH compliant, time-based One-Time-Password (OTP) generator application for the mobile device. It is the client component of Fortinet's highly secure, simple to use and administer, and extremely cost effective two factor solution for meeting your strong authentication needs. This application makes Android and iOS devices (iPhone, iPad or iPod Touch) behave like a hardware-based OTP token without the hassles of remembering and carrying yet another device.
What makes this mobile OTP application superior to others on the market is that while being simple to use for the enduser, and easy to administer and provision for the system administrator, it is actually more secure than the conventional hard token. The token seeds are generated dynamically, minimizing online exposure. Binding the token to the device is enforced and the seeds are always encrypted at rest and in motion.
** You are advised to keep your alternate email address and mobile phone number registered with ITS for the purposes of identity authentication, service event notification and communication with you.**
9738318194