Technical Tip: FortiToken in offline environments
Description
This article describes how to use FortiToken for authentication in offline environments.
Scope
FortiOS, FortiAuthenticator, FortiToken.
Solution
Hardware FortiToken with serial number that does not begin with 'FTK211':
When a Hardware FortiToken serial number is imported to a FortiGate or FortiAuthenticator device, the device automatically retrieves the associated token seed from Fortinet servers. After this is done, the FortiToken can be provisioned to a user without the FortiGate or FortiAuthenticator requiring network access.
Note the online activation method locks online retrieval of the seed file to a particular FortiGate or FortiAuthenticator device. If the token is transferred later, open a ticket with Fortinet Support to unlock the token. See Technical Tip: Hard Token error 'token already activated, and seed won't be returned'.
If needed, the token seed file can also be requested from Fortinet for offline import, see Technical Tip: Process for requesting token seed files for hardware FortiTokens.
Hardware FortiToken with serial number that begins with 'FTK211':
Hardware tokens with a serial number beginning with 'FTK211' (example SKU 'FTK-200CD-10') are shipped with an activation CD including the token seed file, which can be uploaded to the FortiGate or FortiAuthenticator. This CD facilitates the easy offline import of multiple FortiTokens simultaneously and can easily be transferred to multiple FortiGate or FortiAuthenticator devices.
Once the token is shipped, Fortinet does not have access to the seed files for these SKUs. If the seed file is lost, the token can no longer be transferred; see Technical Tip: Lost seed file for FortiToken Hardware with CD.
Without an internet connection, FortiGate and FortiAuthenticator devices can authenticate users locally, using the stored encryption seeds to validate the generated token codes.
This local storage of encryption seeds enables FortiGate and FortiAuthenticator units to maintain their two-factor authentication capabilities even during network outages, ensuring uninterrupted secure access.
FortiToken Mobile:
With one exception, provisioning a mobile FortiToken requires internet access on both the FortiGate or FortiAuthenticator and the user device. After provisioning, the token may be used without network access.
The exception is FortiToken Mobile offline activation using FortiAuthenticator, see Technical Tip: How to activate FortiToken Mobile in an Air Gap network. After initial license retrieval, offline activation does not require internet access to provision a mobile FortiToken to a user.
Token Drift:
Once a FortiToken is provisioned to a user, it does not depend on internet access to generate token codes. However, the system time on the authentication server and the user device must be within 60 seconds.
This can be an issue in environments that do not implement an NTP service. If the token requires manual adjustment, see Troubleshooting Tip: FortiToken OTP drift adjustment.
Notes:
- FortiToken Mobile in the default online activation mode requires connectivity to FortiGuard for performing management tasks, such as assigning tokens to users or making configuration changes. Once a token has been assigned and activated, it will function even if the FortiGate or FortiAuthenticator device loses internet access.
- In contrast, Hardware FortiTokens can be assigned to users without requiring internet access, allowing for offline user management.
- It is critical to safeguard token seeds. This is mostly relevant for hardware FortiTokens, but also applies to FortiToken Mobile in offline activation mode. Unauthorized access to these files could compromise the security of the two-factor authentication system. Always store CDs and seed files in a secure location and restrict access to authorized personnel only.
- FortiToken Mobile online activation codes are not seeds. They are one-time codes to download the token seeds, and for this reason, the activation codes are not considered sensitive after the token is successfully provisioned.
For further inquiries, a ticket should be raised with the Customer Support Team for review and verification.
Related documents:
Technical Tip: Understanding the FortiToken provisioning process
