Skip to main content
kgeorge
Staff
Staff
October 31, 2023

Technical Tip: 'State Error' while assigning FortiToken Mobile to the user

  • October 31, 2023
  • 0 replies
  • 4858 views
Description This article describes how to fix the issue when seeing 'State Error' while assigning a FortiToken Mobile code to the user account, while the same token code shows in Pending status on the FortiToken page.
Scope FortiToken Mobile.
Solution

Check the reachability for FQDNs below from the Firewall using these commands:

 

execute ping fds1.fortinet.com

execute ping directregistration.fortinet.com

 

If they are unreachable, clear the dnsproxy cache and restart it using the commands below:

 

diagnose test application dnsproxy 1
diagnose test application dnsproxy 99

 

Use the commands below to activate the Token Code and renew it:

 

config user fortitoken
    edit <Token Code>
        set status active
end

 

execute fortitoken-mobile renew <Token Code>

 

If getting the following error while renewing the token :

   execute fortitoken-mobile renew <Token Code>
   renew softtoken <Token Code> error -7567

 

The '-7567' error appears when a configuration file is restored from a different FortiGate device. This can occur in situations such as manually migrating a configuration between FortiGate units (with edits to the configuration file), using the FortiConverter service for migration, or uploading a configuration file from another firewall that has a different serial number. This error simply indicates that the token is not valid for the target firewall, meaning it is not licensed for that specific device.

This error can also occur in an HA setup if the FortiToken is registered on the Secondary unit. In this case, an HA failover is required so that the unit holding the token becomes the primary device, after which the token can be renewed.

 

If the issue persists, rebooting FortiGate is suggested. Advise the user to reboot the FortiGate during the downtime window and try removing the tokens and activating it again. Then, assign it to users.

 

Related articles:

Technical Tip: FortiToken basic troubleshooting

Troubleshooting Tip: How to fix a Licensed Mobile Token with an Error/Locked/Provision Timed Out status

Technical Tip: How to assign FortiToken Mobile to users on FortiGate and FortiAuthenticator

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!