Fortinet black logo

Remote authentication using FortiAuthenticator

Remote authentication using FortiAuthenticator

You need to set up both FortiAuthenticator and FortiPortal before you can use FortiAuthenticator for remote authentication.

Configuring FortiAuthenticator

Before using FortiAuthenticator for remote authentication, go to System > Messaging > SMTP Servers in FortiAuthenticator and make certain that the SMTP server is working. If the SMTP server is not working, configure a new SMTP server and then select it in System > Messaging > Email Services.

To configure FortiAuthenticator:
  1. Configure an administrator user or use the default admin user with a valid email address.
  2. Enable Web service access.


  3. Save the REST API key that you will receive by email.
Configuring FortiPortal

When you select Authentication Access as Remote in System > Settings > Authentication, the remote server is set to FortiAuthenticator by default, and the system displays additional settings to configure.

If you change the authentication configuration from local to remote or from remote to local, you must restart FortiPortal.

To configure FortiPortal:
  1. Go to System > Settings > Authentication.
  2. In Authentication Access, select Remote.
  3. In Remote Server, select ForitAuthenticator.
  4. In Remote Server Port, enter 443.
  5. In Remote Server IP Address, enter the IP address of the authentication server.
  6. In Remote Server Key, paste the REST API key you received in email. See step 3 in To configure FortiAuthenticator.
  7. In Domains, add the domain for the administrator user. For example, if the administrator user is abc@test.com, add test.com in Domains.
  8. In Remote Server User field, enter the name of the admin user from step 1 in To configure FortiAuthenticator.
  9. Click Save.

Remote authentication using FortiAuthenticator

You need to set up both FortiAuthenticator and FortiPortal before you can use FortiAuthenticator for remote authentication.

Configuring FortiAuthenticator

Before using FortiAuthenticator for remote authentication, go to System > Messaging > SMTP Servers in FortiAuthenticator and make certain that the SMTP server is working. If the SMTP server is not working, configure a new SMTP server and then select it in System > Messaging > Email Services.

To configure FortiAuthenticator:
  1. Configure an administrator user or use the default admin user with a valid email address.
  2. Enable Web service access.


  3. Save the REST API key that you will receive by email.
Configuring FortiPortal

When you select Authentication Access as Remote in System > Settings > Authentication, the remote server is set to FortiAuthenticator by default, and the system displays additional settings to configure.

If you change the authentication configuration from local to remote or from remote to local, you must restart FortiPortal.

To configure FortiPortal:
  1. Go to System > Settings > Authentication.
  2. In Authentication Access, select Remote.
  3. In Remote Server, select ForitAuthenticator.
  4. In Remote Server Port, enter 443.
  5. In Remote Server IP Address, enter the IP address of the authentication server.
  6. In Remote Server Key, paste the REST API key you received in email. See step 3 in To configure FortiAuthenticator.
  7. In Domains, add the domain for the administrator user. For example, if the administrator user is abc@test.com, add test.com in Domains.
  8. In Remote Server User field, enter the name of the admin user from step 1 in To configure FortiAuthenticator.
  9. Click Save.