VPN (FortiClient)
-
About FortiClient VPN — Including Connection Check
NEW: GlobalProtect VPN and Duo MFA to be retired in April 2025; new VPN, multi-factor authentication services now available What's VPN (Virtual Private Network)? VPN connects students, faculty, and staff to campus-restricted resources. To access VPN, you must use multi-factor authentication (MFA). MFA enhances the security of your Marquette account by using a secondary device to verify your identity. Connection Check: Am I Currently on VPN? Not seeing a result? Go to the article webpage. Install and Use FortiClient VPN and Microsoft Authenticator Install FortiClient VPN on Windows devices Install FortiClient VPN on Mac devices Install FortiClient VPN on iOS devices Install FortiClient VPN on Android devices Set up VPN with Microsoft Authenticator QR Code Enrollment Do's and Don'ts for VPN GlobalProtect VPN/Duo MFA Troubleshooting Confirm GlobalProtect VPN is running on your device. For Windows, check the GlobalProtect icon in the Windows taskbar. For macOS, check the GlobalProtect icon on the top menu bar. Make sure you entered your Marquette username — not email address — and password correctly. In the connect prompt, confirm GlobalProtect lists vpn.marquette.edu in the portal field. Use the "Am I Currently Connected to VPN?" check above to verify your connection status. Have a new mobile device? If your previous mobile device used the Duo mobile app, place a service request to authorize your new device to use Duo. Are you missing a Duo push notification to verify your VPN access? Try these troubleshooting tips. Troubleshooting Duo Push notification issues on iOS devices Troubleshooting Duo Push notification issues on Android devices Getting Help Request Duo Multi-Factor Authentication enrollment email Report a VPN issue Place a service request for questions about VPN
-
Set Up FortiClient VPN for Windows
Follow these instructions to install the FortiClient VPN application on your Windows computer. Before downloading and installing the FortiClient for VPN, please ensure that you have set up Microsoft Authenticator for multi-factor authentication. Instructions for doing so can be found at our site: https://techsquad.mu.edu/support/solutions/articles/21005087234 Step 1: Download the FortiClient Installer Go to https://vpn.mu.edu and log in using your Marquette credentials. Depending upon what type of authentication method you chose for multi-factor authentication, you will be prompted by one of the following ways: 1. If you registered for a phone call to be your second-factor, you will receive a phone call requesting you approve or deny the sign-in attempt. Press the pound key to approve the sign-in. 2. If you registered for a text message to be your second-factor, you will receive a text message that contains a 6-digit verification code. Enter that code in the prompt below. 3. If you registered for App based authentication – notification to be your second-factor, the Authenticator application will push a notification to you prompting for you to approve or deny the sign-in attempt. Click "Approve." If you did not enable notifications from the Authenticator application within your phone's notification settings when you installed it, you will need to open the Authenticator application to get the prompt. Click "Approve" in the prompt within the application. 4. If you registered for App based authentication or hardware token – code to be your second-factor, you will then be asked to enter the 6-digit code found in the Microsoft Authenticator application. You can access the code within the Authenticator application by clicking your profile. In the next screen, the code is listed under “One-time password code.” Enter the one-time passcode in the prompt below and click "Login." Once you have authenticated via multi-factor authentication, you will be directed to a page with a drop-down labeled, “Download FortiClient.” Within the drop-down options, choose “Windows” and the download will begin. The file can be found in your “Downloads” folder once the download is completed. Step 2: Initiate the Installation Process Once the file has been downloaded, go to your “Downloads” folder and run the installer. You will then receive a welcome screen. Click the check box next to “Yes, I have read and accept the License Agreement” and click “Next.” On the next screen, click “Install” to begin the installation. The installation will proceed. When finished, you will be notified. Click “Finish” at this screen. Step 3: Launch FortiClient From the search bar in the bottom left corner, search for and open the FortiClient application. Once the application opens, click the check box next to the acknowledgement, and click “I accept.” Step 4: Configure the VPN Connection The FortiClient panel will open, prompting you to configure a VPN connection. Add a New Connection Click on Configure VPN. Enter VPN Details In the VPN configuration screen, enter the following details: VPN Type: SSL-VPN Connection Name: Marquette VPN Remote Gateway: vpn.mu.edu Click Save to store your VPN configuration. Step 5: Connect to the VPN Authenticate with Your Credentials You will be prompted to enter your username and password. Depending upon what type of authentication method you chose for multi-factor authentication, you will be prompted by one of the following ways: 1. If you registered for a phone call to be your second-factor, you will receive phone call requesting you approve or deny the sign-in attempt. Press the pound key to approve the sign-in. 2. If you registered for a text message to be your second-factor, you will receive a text message that contains a 6-digit verification code. Enter that code in the prompt below. 3. If you registered for App based authentication – notification to be your second-factor, the Authenticator application will push a notification to you prompting for you to approve or deny the sign-in attempt. Click "Approve." If you did not enable notifications from the Authenticator application within your phone's notification settings when you installed it, you will need to open the Authenticator application to get the prompt. Click "Approve" in the prompt within the application. 4. If you registered for App based authentication or hardware token – code to be your second-factor, you will then be asked to enter the 6-digit code found in the Microsoft Authenticator application. Go to the Microsoft Authenticator application on your phone, click your profile, and enter the 6-digit code that appears under “One-time password code” into the prompt. After entering your credentials, click “Ok.” Once the multi-factor authentication has occurred successfully, you will then be connected to the VPN and brought to a page showing your connection information. Subsequent Use of FortiClient For subsequent use of FortiClient, use the search bar in the bottom left corner to find the application and open it, or click the arrow icon within the toolbar in the bottom right corner of your screen and click the FortiClient icon to open the application. There is no need to return to the installation website unless you need to reinstall the software. Troubleshooting If you encounter any issues during the installation or connection process, please contact the IT Services Tech Squad at 414-288-7799 or techsquad@marquette.edu.
-
Set Up FortiClient VPN for macOS
Follow these instructions to install the FortiClient VPN application on your Mac computer. Before downloading and installing the FortiClient for VPN, please ensure that you have set up Microsoft Authenticator for multi-factor authentication. Instructions for doing so can be found at our site: https://techsquad.mu.edu/support/solutions/articles/21005087234 Step 1: Download the FortiClient Installer Go to https://vpn.mu.edu and log in using your Marquette credentials. Depending upon what type of authentication method you chose for multi-factor authentication, you will be prompted by one of the following ways: 1. If you registered for a phone call to be your second-factor, you will receive a phone call requesting you approve or deny the sign-in attempt. Press the pound key to approve the sign-in. 2. If you registered for a text message to be your second-factor, you will receive a text message that contains a 6-digit verification code. Enter that code in the prompt below. 3. If you registered for App based authentication – notification to be your second-factor, the Authenticator application will push a notification to you prompting for you to approve or deny the sign-in attempt. Click "Approve." If you did not enable notifications from the Authenticator application within your phone's notification settings when you installed it, you will need to open the Authenticator application to get the prompt. Click "Approve" in the prompt within the application. 4. If you registered for App based authentication or hardware token – code to be your second-factor, you will then be asked to enter the 6-digit code found in the Microsoft Authenticator application. You can access the code within the Authenticator application by clicking your profile. In the next screen, the code is listed under “One-time password code.” Enter the one-time passcode in the prompt below and click "Login." Once you have authenticated via multi-factor authentication, you will be directed to a page with a drop-down labeled, “Download FortiClient.” Within the drop-down options choose “Mac” and the download will begin. The file can be found in your “Downloads” folder. Step 2: Initiate the Installation Process Once the file has been downloaded, double-click the package to begin the installation process. The Installer will open. Depending on your Mac’s Security settings, you may be prompted by your Mac with the following: “FortiClientInstaller” is an app downloaded from the Internet. Are you sure you want to open it? Click “Open” and the client download will begin. Once the client download has finished, click “Install.” Step 3: Follow the Installation Wizard Click Continue on the welcome screen of the Installer. Agree to the License Agreement Read the End User License Agreement carefully. If you agree to the terms, select “Continue” to proceed. Select Installation Location Choose the location where you would like to install the software. Typically, the default location is suitable for most users. Click “Install.” Your Mac will then ask for your biometrics used for logins or your password. Satisfy either requirement to continue the installation. Allow VPN Configurations The installation process will then begin. During the process if you are on a MacOS version lower than MacOS 15 (Sequoia) you will receive a security prompt requesting access for FortiTray to add VPN Configurations. Click “Allow.” If you are on a MacOS version 15 or higher, you will receive a prompt to allow system software from FortiTray. Click "Cancel." Then go to go to Settings > General > Login Items & Extensions > Network Extensions. Toggle on "FortiTray.app". Step 4: Complete the Installation Once the installation is complete, you will see a confirmation screen. Click Close to finish the process. Step 5: Adjust Security & Privacy Settings After installing FortiClient, you may need to change your Mac’s Privacy & Security settings in order for the FortiClient to properly run. In order to do so, go to the following settings: System Preferences>Privacy & Security>Full Disk Access Find “FortiClient” amongst the list and turn the toggle on next to it. Step 6: Launch FortiClient From the Applications folder, open the FortiClient application. Once the application opens, click the check box next to the acknowledgement, and click “I accept.” Step 7: Configure the VPN Connection The FortiClient panel will open, prompting you to configure a VPN connection. Add a New Connection Click on Configure VPN. Enter VPN Details In the VPN configuration screen, enter the following details: VPN Type: SSL-VPN Connection Name: Marquette VPN Remote Gateway: vpn.mu.edu Click Save to store your VPN configuration. Step 8: Connect to the VPN Authenticate with Your Credentials You will be prompted to enter your username and password. Depending upon what type of authentication method you chose for multi-factor authentication, you will be prompted by one of the following ways: 1. If you registered for a phone call to be your second-factor, you will receive a phone call requesting you approve or deny the sign-in attempt. Press the pound key to approve the sign-in. 2. If you registered for a text message to be your second-factor, you will receive a text message that contains a 6-digit verification code. Enter that code in the prompt below. 3. If you registered for App based authentication – notification to be your second-factor, the Authenticator application will push a notification to you prompting for you to approve or deny the sign-in attempt. Click "Approve." If you did not enable notifications from the Authenticator application within your phone's notification settings when you installed it, you will need to open the Authenticator application to get the prompt. Click "Approve" in the prompt within the application. 4. If you registered for App based authentication or hardware token – code to be your second-factor, you will then be asked to enter the 6-digit code found in the Microsoft Authenticator application. You can access the code within the Authenticator application by clicking your profile. In the next screen, the code is listed under “One-time password code.” Enter the one-time passcode in the prompt below and click "Ok." Once the multi-factor authentication has occurred successfully, you will then be connected to the VPN and brought to a page showing your connection information. Subsequent Use of FortiClient For subsequent use of FortiClient, open the application from your Applications folder and select Connect to initiate the VPN connection. There is no need to return to the installation website unless you need to reinstall the software. Troubleshooting If you encounter any issues during the installation or connection process, please contact the IT Services Tech Squad at 414-288-7799 or techsquad@marquette.edu.
-
Set Up FortiClient VPN for iOS
Follow these instructions to install the FortiClient VPN application on your iOS device. Before downloading and installing the FortiClient for VPN, please ensure that you have set up Microsoft Authenticator for multi-factor authentication. Instructions for doing so can be found at our site: https://techsquad.mu.edu/support/solutions/articles/21005087234 Step 1: Download the FortiClient App Install the FortiClient VPN application from the iOS App Store found here: https://apps.apple.com/us/app/forticlient-vpn/id1475674905 Step 2: Launch the FortiClient App Open the FortiClient application. Click “Connection.” You will be brought to a screen that requests you select a VPN connection. Click “Add Configuration.” Step 3: Configure the VPN Connection The app will then request you configure the VPN Account Information. Please enter the following: Security Protocol: SSLVPN Name: Marquette VPN Server Address: vpn.mu.edu SSO: (Toggle off) Port: 443 Use Certificate: (Toggle off) Username: (Your Marquette username) Once you have entered the configuration above, click “Save” at the top right corner. Step 4: Connect to the VPN Back at the VPN home screen, toggle on the option labeled “Connect.” You will be prompted to enter your Marquette credentials. Enter your credentials and click “Ok.” Depending upon what type of authentication method you chose for multi-factor authentication, you will be prompted by one of the following ways: 1. If you registered for a phone call to be your second-factor, you will receive a phone call requesting you approve or deny the sign-in attempt. Press the pound key to approve the sign-in. 2. If you registered for a text message to be your second-factor, you will receive a text message that contains a 6-digit verification code. Enter that code in the prompt below. 3. If you registered for App based authentication – notification to be your second-factor, the Authenticator application will push a notification to you prompting for you to approve or deny the sign-in attempt. Click "Approve." If you did not enable notifications from the Authenticator application within your phone's notification settings when you installed it, you will need to open the Authenticator application to get the prompt. Click "Approve" in the prompt within the application. 4. If you registered for App based authentication or hardware token – code to be your second-factor, you will then be asked to enter the 6-digit code found in the Microsoft Authenticator application. You can access the code within the Authenticator application by clicking your profile. In the next screen, the code is listed under “One-time password code.” Enter the one-time passcode in the prompt below and click "Ok." Once multi-factor authentication has been successful, you will then be connected to the VPN and brought to a page showing your connection information. Subsequent Use of FortiClient For subsequent use of FortiClient, open the application and toggle on the option labeled “Connect.” There is no need to enter the configuration information again after the initial setup. Troubleshooting If you encounter any issues during the installation or connection process, please contact the IT Services Tech Squad at 414-288-7799 or techsquad@marquette.edu.
-
Set up FortiClient VPN for Android
Follow these instructions to install the FortiClient VPN application on your iOS device. Before downloading and installing the FortiClient for VPN, please ensure that you have set up Microsoft Authenticator for multi-factor authentication. Instructions for doing so can be found at our site: https://techsquad.mu.edu/support/solutions/articles/21005087234 Step 1: Download the FortiClient App Install the FortiClient VPN application from the Google Play Store found here: https://play.google.com/store/apps/details?id=com.fortinet.forticlient_vpn&pcampaignid=web_share Step 2: Launch the FortiClient App Open the FortiClient application. A privacy prompt will appear. Click "I accept." A notifications prompt will then appear. Choose "Allow" or "Do not Allow" based upon your preference. The application will then request you enable "Unrestricted battery usage." Click "Enable." Step 3: Configure the VPN Connection You will then be brought to a page for configuring the VPN. Please enter the following information in the corresponding fields: Input the VPN Name: Marquette VPN VPN Type: SSL VPN Once you have entered this configuration click "Create" A new configuration page will now appear. Please enter the following information into the corresponding fields: Servers: vpn.mu.edu Port: 443 Username: (your Marquette username) Certificate: X.509 certificate in PKCS12 format Single Sign On: Disabled Prompt User Credentials: Enabled After you have entered the configuration, click the back button and you will be brought to the home screen with the VPN now set up. Step 4: Connect to the VPN Click "Connect" and the application will then ask for your credentials. Enter your Marquette username and password, and then click "Login." You will then receive a prompt for a connection request. You will only receive this prompt upon the initial login, and not any subsequent logins. Click "Ok." You will then receive a prompt regarding the certificate. Click "Proceed." Depending upon what type of authentication method you chose for multi-factor authentication, you will be prompted by one of the following ways: 1. If you registered for a phone call to be your second-factor, you will receive a phone call requesting you approve or deny the sign-in attempt. Press the pound key to approve the sign-in. 2. If you registered for a text message to be your second-factor, you will receive a text message that contains a 6-digit verification code. Enter that code in the prompt below. 3. If you registered for App based authentication – notification to be your second-factor, the Authenticator application will push a notification to you prompting for you to approve or deny the sign-in attempt. Click "Approve." If you did not enable notifications from the Authenticator application within your phone's notification settings when you installed it, you will need to open the Authenticator application to get the prompt. Click "Approve" in the prompt within the application. 4. If you registered for App based authentication or hardware token – code to be your second-factor, you will then be asked to enter the 6-digit code found in the Microsoft Authenticator application. You can access the code within the Authenticator application by clicking your profile. In the next screen, the code is listed under “One-time password code.” Enter the one-time passcode in the prompt below and click "Ok." Once multi-factor authentication has been successful, you will then be connected to the VPN and brought to a page showing your connection information. Subsequent Use of FortiClient For subsequent use of FortiClient, open the application and toggle on the option labeled “Connect.” There is no need to enter the configuration information again after the initial setup. Troubleshooting If you encounter any issues during the installation or connection process, please contact the IT Services Tech Squad at 414-288-7799 or techsquad@marquette.edu.
-
Do's and Don'ts for VPN
VPN (Virtual Private Network) gives access to campus-restricted resources while away from Marquette University. Learn more about VPN. Do use VPN for: Securing your network connection when using public Wi-Fi Accessing these Marquette resources from off-campus: MyJob Financial System and Employee Self Service Some library resources (although many can be reached with just your Marquette username and password) MarqIt (University Advancement CRM) Perceptive Content/ImageNow document imaging system Modern Campus CMS and Adobe Contribute/Dreamweaver web authoring Campus-restricted websites such as Purchasing and Comptroller AMOS and Minitab (statistical software) Various college specific systems Don't use VPN for: Accessing Marquette resources that don't require VPN — unless you are using public Wi-Fi. Examples include: Microsoft 365 (email, Microsoft Teams, OneDrive for Business, SharePoint) CheckMarq D2L e-learning EmpCenter timekeeping MARQetplace e-procurement Kuali Research
-
Set up Forticlient VPN on Linux (No support)
Before downloading and installing the FortiClient for VPN, please ensure that you have set up Microsoft Authenticator for multi-factor authentication. Instructions for doing so can be found at our site: https://techsquad.mu.edu/support/solutions/articles/21005087234 1. Download SSL VPN Client for Linux. The latest SSL VPN Client for Linux can be downloaded from Product Downloads and Free Trials. To download the software: Open the link: Product Downloads and Free Trials Scroll-Down to FortiClient VPN and download the .deb or .rpm build. 2. Via Linux Terminal, go to the folder where the file has been downloaded and using the package manager install the FortiClient. To install on Ubuntu: In a terminal window, run the following command: $ sudo apt-get install To install on Fedora: In a terminal window, run the following command: $ sudo dnf install -y 3. Configuration of the GUI FortiClient SSL VPN. Type the hostname (vpn.mu.edu) of FortiGate and port (443), username/password and select ‘Connect’. If the SSL VPN connection requires Proxy, certificate or other advance settings, select ‘Settings’. Under ‘Settings’, more SSL VPN profiles can be added by selecting ‘+’ button. If a certificate warning is displayed, select ‘Continue’ to proceed. Once connected, check which IP has been assigned by running ‘ifconfig’. The name of the interface is ppp0 and the routing table with ‘route’ 4. Configuration of the CLI SSL VPN Client: Run ./forticlientsslvpn_cli to display all available configuration options If the SSL VPN connection only requires username/password, run: ./forticlientsslvpn_cli --server vpn.mu.edu:443 --vpnuser . Press Enter and FortiClient will request the password for the username. If the connection is successful, a STATUS::Connected message will be displayed, otherwise if the password is incorrect, error ‘SSLVPN down unexpectedly with error:2’ will appear.