Skip to main content
Muttahar_Rehman
Explorer II
August 17, 2026
Solved

Do not want cached credential in ZTNA Forticlient

  • August 17, 2026
  • 15 replies
  • 154 views

FortiEMS 8.0 managed FortiClient 7.4.7 using FortiTokken.

after first time enter user and password details it don’t ask again user credential only fortiTokken.But as per compliance i have to configure like fortiClient ask everytime user password .


i already disable the option save pasword and auto login. still same and in fortiClient (Save login) grayed.

Best answer by Muttahar_Rehman

Now connected VPN i did the steps which is below:

set client-auto-negotiate enable
disconnect ems 
complete shutdown agent
again initiate new inivitation code
connect ems 
then clear cookies
now VPN showing password pop-up and then Tokken pop-up
Connected VPN successfully.

15 replies

Muttahar_Rehman
Explorer II
August 17, 2026

even after i change the user password and try to connect vpn . it shows me error credentials not correct not showing pop up to enter new password.

Thanks, R3hsec
funkylicious
SuperUser
SuperUser
August 17, 2026

Are you refering to a published ZTNA application or while connecting to VPN ?

If its a IPsec VPN, is it using SAML ? 

"jack of all trades, master of none"
Muttahar_Rehman
Explorer II
August 18, 2026

connecting vpn
yes its ipesc vpn not using SAML simple fortitokken 

Thanks, R3hsec
sjoshi
Staff
Staff
August 17, 2026

are you using saml?

is it with ipsecvpn with saml with ikev2?

Thanks, Salon
Muttahar_Rehman
Explorer II
August 18, 2026

No,

ipsec ikev2 not using saml

Thanks, R3hsec
sjoshi
Staff
Staff
August 18, 2026

what kind of authentication you are using

local or radius or ldap?

Thanks, Salon
Muttahar_Rehman
Explorer II
August 18, 2026

ldap for domain user radius for vendor user

Thanks, R3hsec
sjoshi
Staff
Staff
August 18, 2026

can you try disable this saveoption in the ems 

 

For IPsec:ON  FGT
 
config vpn ipsec phase1-interface
    edit [vpn name]
        set save-password disable
        set client-auto-negotiate disable
        set client-keep-alive disable
    end
end
Thanks, Salon
Muttahar_Rehman
Explorer II
August 19, 2026

i already did it will do it again and update

Thanks, R3hsec
funkylicious
SuperUser
SuperUser
August 19, 2026

i would consider opening a TAC ticket in your situation.

"jack of all trades, master of none"
Muttahar_Rehman
Explorer II
August 20, 2026

after run this below command:
  set client-auto-negotiate disable
        set client-keep-alive disable


pasword pop-up showing now but vpn connection timeout.

 

Thanks, R3hsec
Muttahar_Rehman
Muttahar_RehmanAuthorAnswer
Explorer II
August 20, 2026

Now connected VPN i did the steps which is below:

set client-auto-negotiate enable
disconnect ems 
complete shutdown agent
again initiate new inivitation code
connect ems 
then clear cookies
now VPN showing password pop-up and then Tokken pop-up
Connected VPN successfully.

Thanks, R3hsec
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!