Fortinet white logo
Fortinet white logo

Admin Guide

26.2.0

Activating FGT VDOMs for FIC service

Activating FGT VDOMs for FIC service

In order for your FortiGate (FGT) users to take advantage of the MFA feature provided by FortiIdentity Cloud, make sure that FIC service is enabled on the FGT device.

By default, FortiIdentity Cloud service is enabled in FortiOS. However, if for some reason, FIC is not enabled on your FGT, you must manually enable it to proceed.

Tooltip

Only an FGT global admin user can activate FIC service on a per-FGT device basis, not by specific VDOMs.

FortiGate-VM64 # config global
FortiGate-VM64 (global) # config system global
FortiGate-VM64 (global) # set fortitoken-cloud enable
FortiGate-VM64 (global) # end

"set fortitoken-cloud enable" is a "local" command and does not trigger communication with the FIC server. It simply enables FGT VDOM admin users to manage FIC users locally using the FGT CLI.

Activating FGT VDOMs for FIC service

Activating FGT VDOMs for FIC service

In order for your FortiGate (FGT) users to take advantage of the MFA feature provided by FortiIdentity Cloud, make sure that FIC service is enabled on the FGT device.

By default, FortiIdentity Cloud service is enabled in FortiOS. However, if for some reason, FIC is not enabled on your FGT, you must manually enable it to proceed.

Tooltip

Only an FGT global admin user can activate FIC service on a per-FGT device basis, not by specific VDOMs.

FortiGate-VM64 # config global
FortiGate-VM64 (global) # config system global
FortiGate-VM64 (global) # set fortitoken-cloud enable
FortiGate-VM64 (global) # end

"set fortitoken-cloud enable" is a "local" command and does not trigger communication with the FIC server. It simply enables FGT VDOM admin users to manage FIC users locally using the FGT CLI.