Troubleshooting Tip: Unable to login to the SSL VPN/IPsec VPN using 2FA for new users
Description | This article describes how to handle a scenario where the user is unable to connect to the SSL VPN/IPsec VPN using 2FA when FortiTokens are assigned. |
Scope | FortiGate, FortiToken Mobile. |
Solution | When checking the SSL VPN/IKE debugs, the logs will show 'Token check failed' even though the user is authenticated successfully using RADIUS/LDAP:
To deactivate a FortiToken for the user, see this document: Deactivating a FortiToken. To assign FortiToken to a user: ![]()
To assign FortiToken to a local user via CLI:
Note: For IPsec dial-up VPN connections, if a token is reassigned to a user and authentication issues persist (e.g., intermittent connection or failed login), it is recommended to increase the authentication/negotiation timeout. This allows remote users sufficient time to enter the one-time password (OTP) during the authentication process: Technical Tip: Adjusting IPsec negotiation timeout. Related article: Technical Tip: Correctly configuring Two-Factor Authentication for LDAP users using SSL VPN |

