Description | This article describes an issue where two-factor authentication via FortiToken Cloud (or FortiIdentity Cloud) fails for all users after changing the HA cluster mode from Active-Passive/Active-Active to Standalone. |
Scope | FortiGate, FortiToken Cloud. |
Solution |
In the event where the FortiGate HA cluster mode was changed from Active-Passive/Active-Active to Standalone, users trying to login with 2FA via FortiToken Cloud will experience failed logins due to unknown 2FA.
In some instances, the experience on the user side will be an immediate failure of 2FA despite not yet entering any code.
Where :
When the HA cluster mode is changed to 'Standalone', 2FA logins made by a user that has a FortiToken under the realm 'FGTA-FGTB-root' will fail (status: 400) and be tagged as 'unknown 2FA' in the FortiToken Cloud Authentication logs.
This is because FortiToken Cloud now checks the 2FA logins made by the user under a different realm, 'FGTA-root'. This is the new realm automatically built in FortiToken Cloud after shifting the HA cluster mode to 'Standalone'.
To fix the issue, the administrator needs to re-provision the FortiToken to the user in FortiGate by disabling and re-enabling 2FA via FortiToken Cloud. The user will need to complete the FortiToken provisioning process for the FortiToken to be properly assigned.
The user will then be automatically assigned to the "FGTA-root" realm in FortiToken Cloud, and 2FA logins will be successful once again.
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.