Created on
11-08-2024
10:48 AM
Edited on
04-15-2025
07:25 AM
By
SimranRana
Description | This article describes how to set up a FortiToken for 2FA when the FortiGate is air-gapped. |
Scope | FortiGate. |
Solution |
In order to activate the FortiToken, the activation code is needed. This is generally sent to users via email, but if the FortiGate is air-gapped (no internet), this is generally not possible. However, it is possible to see the contents of the email the FortiGate attempts to send out, even if there is no internet connection.
Run the following debug commands to see the contents of the email the FortiGate sends out:
diagnose debug reset diagnose debug console timestamp enable
To stop the debug, run the following commands:
diagnose debug disable diagnose debug reset
Here is the output after sending the email. The activation code is visible and this can be put into the FortiToken application.
The activation code can also be obtained from the System Event logs as FortiGate records the action and content of FortiToken activation sent to the end-user:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.