FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
SimranRana
Staff
Staff
Article Id 405523
Description This article describes the steps to delete FortiTokens in bulk, which is particularly helpful in scenarios where FortiTokens are being migrated from one device to another.
Scope FortiGate, FortiToken.
Solution

While migrating the FortiToken from one device to another, it is necessary to delete the tokens from the old unit and then register the Tokens on the new unit for assigning to the users.

 

To delete the FortiTokens on the old unit, remove their references first. See Technical Tip: Removing old FortiToken references from users in bulk.

 

After the references have been removed, follow the steps below to create a script to delete these FortiTokens in Bulk:

 

  1. Run the following command on the CLI to get the FortiToken list.

 

show user fortitoken

 

  1. Copy all the FortiTokens listed in Notepad++.

KB1.png

 

  1. On Notepad++, navigate to Plugins -> Plugins Admin -> Available and search for LineFilter to install.

KB2.png

 

  1. Once the plugin is installed on Notepad++, navigate to Plugins -> Line Filter -> Advanced -> Select 'Keep' -> Select 'Text Search' and then enter 'edit' in 'Lines that do contain:' option.

 

KB3.png

 

  1. After clicking on Perform, it will create a new file with all the FortiTokens listed. Access Search -> Replace or Press 'CTRL + H ' and Replace All <edit> with <delete>:

KB4.png

 

Result:

 

KB5.png

 

  1. Add 'config user fortitoken' at the beginning and 'end' at the end of this file, and save this to run as a script.

 

KB6.png

 

  1. In the FortiOS GUI, in the top right corner, select the admin user Configuration -> Script -> Run Script, upload the saved file, and select OK.

This script will remove the FortiTokens in bulk on the old unit, and the FortiTokens will be ready for activation and assignment on the new unit.

Related article:
Technical Tip: Migrating users and FortiTokens to another FortiGate/FortiAuthenticator