Technical Tip: FortiToken Mobile cannot be provisioned after upgrading FortiGate to v7.4.9 and v7.6.5
| Description | This article describes an issue where administrators are unable to assign or provision FortiToken Mobile tokens to users after upgrading the FortiGate firmware to version 7.4.9 or 7.6.5 |
| Scope | FortiGate v7.4.9, v7.6.5, FortiToken. |
| Solution | A FortiToken license must be registered to a FortiGate serial number. In a cluster with two or more FortiGate units, FortiTokens can be shared across the cluster, even if the unit to which the tokens are registered is operating as the secondary unit. However, after upgrading the FortiGate firmware to version 7.4.9 or 7.6.5, administrators are unable to assign or provision FortiToken Mobile tokens to users if the FortiToken license is not registered to the primary (active) unit in the cluster. For example, if FortiTokens are registered to the serial number of FortiGate-A, but FortiGate-B is the active unit in the cluster, FortiToken provisioning will fail after upgrading to version 7.4.9 or 7.6.5. To determine whether a FortiGate cluster is impacted by this known issue, run the following debug commands and attempt to assign an available FortiToken to a user (via GUI or CLI):
diagnose fortitoken debug enable The following logs can be seen in the debug output:
On FortiOS v7.4.9:
"__device_version":"7.0","__device_build":"2829","__clustered_sns":[{"sn":"FG10E1TB20******","error":null}],"tokens":[{"token":"FTKMOB2A0******","license":null,"token_activation_code":null,"qr_code":null, "code_expire":null,"error":{"error_code":31,"error_message":"token does not belong to product"}}],"result":0,"error":{"error_code":17,"error_message":"no valid token found"}}}
On FortiOS v7.6.5 or v7.6.6:
ftm_cfg_provision_token[426]:provision token: FTKMOB******
If only a single FortiGate serial number appears in the '__clustered_sns field', the cluster is affected by this issue. On FortiOS v7.4.8 or below:
The serial numbers of both FortiGate units in the HA cluster are displayed in the '__clustered_sns' field in the working scenario. This issue has been resolved in: v7.6.7 (scheduled to be released in May 2026). Workaround: Note: This issue is specifically observed on FortiGate models that currently do not support the Virtual Serial Number (vSN) feature (Single FortiGuard license for FortiGate A-P HA cluster). |