FortiToken in a-p HA environment
Does anybody know if anything has just changed on FTNT side in case FortiToken/FortiToken Mobile is deployed on FGTs in a-p environment?
We've been deploying FortiToken Mobile to multiple customers with our a-p HA FGT environment for at least last 5 years or so. When we get a new licenses for 10, 20, 100 tokens we just activated it at the primary FGT without registering it to any one of FGT at the support site. It had been working fine until recently when a customer couldn't assign an available tokens to any SSL VPN users because it errors out. With a TAC ticket we found those licenses were registered to the secondary unit somehow. So we had to get them moved to the primary unit by CS and removed "Error" tokens and reapplied the activation-key to recover them.
However, we never registered them at the secondary unit, or even at the primary, as I said above and we haven't seen those licenses at the asset page before. Now the biggest problem is when a-p swapover happens, we have to get all of them moved to the new primary in a hurry. Is this the intended new token operation in HA?
Obviously doubling token licenses and registering at all secondary units would not work because those would have different token numbers from the primaries'.
This would half-kill the purpose/benefit of a-p HA and everybody who use a-p HA, regardless how small the units are, and tokens would be forced to deploy ForetiAuthenticator. So I'm hoping this is some kind of error happened at FortiGuard, which does the license/token validation, and soon go back to previous state.
Toshi
