FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
warshad
Staff
Staff
Article Id 219162
Description This article describes that when the push function is used, the following error message 'Token denied or timeout (-7105)' is displayed and authentication may not be received.
Scope FortiGate.
Solution

This error occurs because the data pushed by the FortiToken Mobile App ('Approve' or 'deny') does not arrive at the corresponding FortiGate.

 
 

Screenshot_20220731-170152_FortiToken Mobile.jpg

 

Check the following:

  • The FortiGate IP is entered correctly in the FortiGate's ftm-push settings.
  • If FortiGate IP DNAT is set from the top with the correct public IP address.
  • 'FTM' is set in allowaccess for FortiGate interface setting.
  • 'Trusthost' is set up in FortiGate Manager.

 

Push data is data accessed from the outside to FortiGate.  If 'Trusthost' is set, the source IP of the push data is not included in Trusthost, so it will be blocked.

 

If this is the case, it is possible to add an administrator account without Trusthost configuration.

 

If FortiToken Cloud is used, push can be used even if all administrators have set up Trusthost.