How to Implement Two-Factor Authentication for SSL VPN with FortiToken and LDAP
An organization is implementing two-factor authentication for SSL VPN access using FortiToken. Which THREE components are necessary for this setup?
⚠ Common exam trap
Many candidates assume an external authentication server (LDAP or RADIUS) is mandatory for two-factor authentication, but FortiGate can validate FortiTokens locally without any external server.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A firewall policy that requires authentication and references the user group
A firewall policy must reference the user group that has two-factor authentication enabled. The policy enforces authentication for SSL VPN traffic, and without this reference, the FortiGate would not require the user to authenticate via FortiToken, defeating the purpose of two-factor authentication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
An LDAP server for user synchronization
Why it's wrong here
An LDAP server is not a mandatory component for FortiGate two-factor authentication; the FortiGate can authenticate local users directly. LDAP would only serve as the identity source for the first factor (password) and does not participate in FortiToken validation. Therefore, while LDAP can be integrated for user synchronization or password lookup, it is not required to implement the two-factor solution with FortiToken.
- ✓
A firewall policy that requires authentication and references the user group
Why this is correct
The firewall policy is the enforcement point that triggers the authentication process. When a user attempts to match a policy that requires authentication, the FortiGate prompts for credentials and validates them against the referenced user group. Because the policy references the user group with two-factor enabled, it forces the user to provide both the password and the FortiToken code, making this policy a necessary component.
- ✓
A FortiToken assigned to the user
Why this is correct
A FortiToken is the possession-factor device that generates one-time passcodes (OTPs). It is assigned to each user and serves as the second authentication factor, complementing the user's password (knowledge factor). Without a FortiToken, the user would only have a single factor, so the token is critical for true two-factor authentication.
- ✓
A user group with two-factor authentication enabled
Why this is correct
The user group is the container that defines which users are subject to two-factor authentication. When two-factor authentication is enabled on the group, the FortiGate requires each member to validate a FortiToken code in addition to their password. The firewall policy references this specific group, so the group configuration is what enforces the two-factor requirement for the affected traffic.
- ✗
A RADIUS server for token validation
Why it's wrong here
A RADIUS server is unnecessary for FortiToken validation because the FortiGate processes and validates OTP codes locally. RADIUS is designed for external authentication services (such as LDAP or a third-party token server), but FortiToken validation is always handled by the FortiGate itself. Introducing a RADIUS server would add complexity and is not part of the intended two-factor deployment with FortiToken.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.