Primary VPN - Certificate Based
Once you are initially configured, the primary VPN will allow you to connect without entering a password or needing a Duo prompt.
In the lower right corner of your screen, look for the blue shield icon. You might have to click the ^ icon first to find it. When you hover your mouse over it, it should say FortiClient and a version number.

Click on the shield.
You should see Connect to "IUPAT VPN 2026" listed.

Click on Connect to "IUPAT VPN 2026". If you have previously connected you shouldn't have to do anything else, you will just see a message that you are connected. If it does not connect automatically, it is likely that it is not choosing the correct certificate for you.
If The Initial Connection Fails - Choose Certificate
Click on the FortiClient shield icon again, but this time choose "Open FortiClient Console". When the console opens, click "Remote Access" on the right and choose the "IUPAT VPN 2026" in the VPN Name dropdown. Verify that the Client Certificate is showing your name and "iupat-CA02-CA", if not select it and click Connect.

If the connection still fails you can try rebooting your machine or move to the password VPN as outlined below.
Password and Duo VPN - will be discontinued soon
Click on the FortiClient shield icon as above, but this time choose "IUPAT VPN".
The FortiClient console will open; you should see the VPN logon screen. If you see anything else, click on Remote Access on the left side.
Type your username and your password. This is the same password you use to log in to your computer.
Click Connect. You will need to respond to the Duo push on your mobile device.

When connected, you will see the following pop-up in the lower right corner of your screen:

Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article