Configuring a user
To configure a user:
- Go to Security > Firewall Objects.
- Select User from the User & Device dropdown.
- Click Create or select an existing user from the list and click Edit..
- In the form, enter the following information:
Settings
Guidelines
User Name
Required. Enter a name for the user.
Disable
Enable to disable the user.
Password
Enter the password.
Contact Information
Email
Enter the email address.
Two-factor Authentication
Select from the following:
Disable
FortiToken: From the dropdown, select a FortiToken.
See FortiToken.
Email based two-factor authentication.
- Click Save.
FortiToken
FortiToken is a one-time password (OTP) generator, available as a physical device or a mobile phone application. It generates a six-digit authentication code used together with a username and password for two-factor authentication.
FortiTokens can be added to user accounts that are local, IPsec VPN, SSL VPN, and even Administrators.A FortiToken can be associated with only one account on one FortiPortal unit.
If a FortiToken is lost, your account can be locked so that it will not be used to falsely access the network.
Email based two-factor authentication
Two-factor email authentication sends a randomly generated six digit numeric code to the specified email address. Enter that code when prompted at login. This token code is valid for 60 seconds. If you enter this code after that time, it will not be accepted.
A benefit is that you do not require mobile service to authenticate. However, a potential issue is if your email server does not deliver the email before the 60 second life of the token expires.
The code will be generated and emailed at the time of login, so you must have email access at that time to be able to receive the code.