Technical Tip: 'State Error' while assigning FortiToken Mobile to the user
| Description | This article describes how to fix the issue when seeing 'State Error' while assigning a FortiToken Mobile code to the user account, while the same token code shows in Pending status on the FortiToken page. |
| Scope | FortiToken Mobile. |
| Solution | Check the reachability for FQDNs below from the Firewall using these commands:
execute ping fds1.fortinet.com execute ping directregistration.fortinet.com
If they are unreachable, clear the dnsproxy cache and restart it using the commands below:
diagnose test application dnsproxy 1
Use the commands below to activate the Token Code and renew it:
config user fortitoken
execute fortitoken-mobile renew <Token Code>
If getting the following error while renewing the token :
The '-7567' error appears when a configuration file is restored from a different FortiGate device. This can occur in situations such as manually migrating a configuration between FortiGate units (with edits to the configuration file), using the FortiConverter service for migration, or uploading a configuration file from another firewall that has a different serial number. This error simply indicates that the token is not valid for the target firewall, meaning it is not licensed for that specific device.
If the issue persists, rebooting FortiGate is suggested. Advise the user to reboot the FortiGate during the downtime window and try removing the tokens and activating it again. Then, assign it to users.
Related articles: Technical Tip: FortiToken basic troubleshooting Technical Tip: How to assign FortiToken Mobile to users on FortiGate and FortiAuthenticator |
