FortiAuthenticator
FortiAuthenticator provides centralized authentication services for the Fortinet Security Fabric including multi-factor authentication, single sign-on services, certificate management, and guest management.
kwcheng__FTNT
Article Id 413496
Description This article describes how to troubleshoot and resolve the issue of the SNMP server not receiving the correct trap, specifically with the FortiAuthenticator when expecting a User lockout, but instead receiving an IP lockout SNMP trap or vice versa.
Scope FortiAuthenticator.
Solution

To troubleshoot and resolve the issue of the SNMP server not receiving the correct trap, follow these steps (if the 'facTrapUserLockout' trap is needed):

  1. Go to FortiAuthenticator -> Authentication -> User Account Policies -> Lockout.
  2. Disable the IP lockout setting.
  3. Enable the User lockout setting.
  4. Save the changes.
  5. Go to FortiAuthenticator -> Monitor -> Authentication -> Lockout IP Address.
  6. Unlock the test entry from the IP address.
  7. Test the SNMP trap again.

These steps should resolve the issue of the SNMP server not receiving the correct trap related to 'facTrapUserLockout'. If 'facTrapIPLockout' is needed, just reverse the steps above.