- On the FortiAuthenticator, go to Authentication > RADIUS Service > Clients, and select Create New to add the FortiGate as a RADIUS client.
- Enter a Name (OfficeServer), the IP address of the FortiGate, and set a Secret.
The secret is a pre-shared secure password that the FortiGate will use to authenticate to the FortiAuthenticator.
- Click OK.
- Go to Authentication > RADIUS Service > Policies, and select Create New.
- Enter the RADIUS policy name, description, and select the FortiGate RADIUS client.
- Optionally, configure RADIUS attribute criteria.
- Choose Password/OTP authentication as the authentication type.
- Choose a username format (in this example:
username@realm), and select the Local realm.
- Set the authentication method to Mandatory two-factor authentication, and enable the Allow FortiToken Mobile push notifications option.
- Click Save and Exit.
Note the Username input format. This is the format that the user must use to enter their username in the web portal, made up of their username and realm. In this example, the full username for gthreepwood is