Description
FortiGate is shipped with two free FortiTokens Mobile per unit with unique serial numbers. This works very similar to the bought licenses with the EFTMxxx numbers, it will have a real activation code.
Scope
Solution
If there is an activation code, then on GUI, create a new Hard Token or Mobile Token:
The same steps can be followed on FortiAuthenticator 'Importing Trial Tokens' or adding a license file for FortiToken Mobile or Hardware token.
Importing trial tokens in FortiAuthenticator
In order to import trial tokens on FortiAuthenticator it is necessary to have internet reachability to connect with FortiGuard servers.
From CLI on FortiGate:
execute fortitoken-mobile import 0000-0000-0000-0000-0000
From CLI:
config system email-server
set server "notification.fortinet.net"
set port 465
set security smtps
end
Enable authentication if it is required by the server to send email messages.
If a security mode is selected, make sure the TLS tunnel can come up by importing the custom mail server's CA to the FortiGate's CA store.
Configure an SMS server for sending SMS messages to support user authentication.
config system sms-server
edit <name>
set mail-server {string}
next
end
Troubleshooting notes:
If the token selection is empty on the user profile:
Solution :
FortiGates in FIPS-CC mode may have issues when activating FortiToken Mobile licenses while using the Anycast FortiGuard servers. Check for the following error in the FortiToken process debugs, and if present, then disable FortiGuard Anycast and retry FortiToken Mobile activation (see Technical Tip: FortiGuard is not reachable via Anycast default method).
diagnose debug console timestamp enable
diagnose fortitoken debug enable
diagnose debug enable
2025-09-02 12:09:41 ftm_cfg_import_license[353]:import license XXXXXXXXXXXXXX
2025-09-02 12:09:41 ftm_fc_comm_connect[49]:ftm TCPS conn failed: ssl_connect() failed: 5 (Success)
2025-09-02 12:09:41 ftm_fc_command[588]:forticare [globalftm.fortinet.net:443] unreachable
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.