FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
gonzalezw
Staff
Staff
Article Id 332464
Description This article describes how to migrate a FortiToken from an old phone to a new one when the transfer option does not work.
Scope FortiGate.
Solution

Note:

This article assumes that there is administrative access or equivalent access to the FortiGate at the time of deleting the existing token from the mobile device.

  1. Delete the existing token from the FortiToken mobile app: Open the app on the Android/iPhone. Then, select the three dots located in the top right corner.

 

Fortitoken mobile 1.png

 

  1. Select Manage and press the red X next to the FortiToken Serial Number.

 

FortiToken.jpg

 

  1. At this stage, the FortiToken Serial Number has been removed from the FortiToken app. Go to User & Authentication -> User Definition to send the email to receive the QR code to register the FortiToken in the new device.

 

FortiToken 2.jpg

 

  1. Once the user has been selected, select 'Send Activation Code Email'.

 

FortiToken 3.jpg

 

 

  1. If FortiGate fails to send the activation code email, disable the 'Two-factor Authentication' toggle button and re-enable it. Choose the same or another available FortiToken, and get the email.
  2. Open the QR code file in the FortiToken app on the new phone and scan the given QR code. The token should have been migrated to the new phone device:

 

FortiToken 4.jpgAdditional note:

There are instances when FortiAuthenticator is used instead of FortiGate for remote authentication. As such, if the remote user wants to migrate a mobile FortiToken from an old phone to a new one on FortiAuthenticator, not FortiGate, navigate to Authentication -> User Management -> Remote Users -> Enable One-Time Password (OTP) authentication -> FortiToken -> Mobile > Email on FortiAuthenticator, as shown below:

 

FortiAuth, Not Fortigate.jpg

 

Open a TAC case if further assistance is required.

Comments
GILMENDO
Staff & Editor
Staff & Editor

Excellent and necessary thank you! @gonzalezw