FortiAuthenticator
FortiAuthenticator provides centralized authentication services for the Fortinet Security Fabric including multi-factor authentication, single sign-on services, certificate management, and guest management.
Jackie_T
Staff
Staff
Article Id 339695
Description

This article describes how to troubleshoot the issue of service unreachable for the FortiToken Cloud after 7th September 2024.

Scope

FortiAuthenticator, FortiToken Cloud.

Solution

There is a change of public IP for the FortiToken Cloud server on 7th September 2024 as per the announcement made:

 

'FortiToken Cloud primary data center will move to a new public IP address: 69.167.109.248. This is in place of 173.243.137.31. IP address 206.47.184.22 will remain unchanged'.

 

In some environments where network access is strict, FortiAuthenticator might encounter an error for FortiToken Cloud Service unreachable as below:

 

FAC2.png

 

When trying to ping from FortiAuthenticator to the server (ftc.fortinet.com), it is possible to see if it is ping-able or resolved to an IP. This IP could be different from what the IP was previously.

 

When doing tcpdump or packet sniffer on the FortiAuthenticator, it is possible to see the traffic is only one way, i.e. packet sending out to FortiToken Cloud server but no response. It is because of the single IP address 173.243.137.31 allowed (the former primary IP) in the network environment.

 

To solve this problem, make sure to allow both the new primary IP and the secondary IP: 69.167.109.248 and 206.47.184.22, for TCP port 8686 in the network environment, for FortiAuthenticator to communicate with the FortiToken Cloud server.

Contributors