FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
ppatel
Staff & Editor
Staff & Editor
Article Id 195198

Description

 

This article describes how to move the Mobile FortiTokens from one FortiGate to another during the migration.
After migration of the configuration from the old FortiGate to the new one, the Fortitokens mobile will not be working for the user authentication.

 

Scope

 

FortiGate, FortiToken.

Solution


FortiGate does not support the migration of the FortiTokens mobile from the old to the new unit.

Once the configuration is migrated, the FortiToken mobile license(s) need to be moved from the old unit to the new one.
It can be done by creating a support ticket with Fortinet CSS.

Once the license is moved to the new unit:

  1. The FortiTokens on the new FortiGate should be unbound from the users.
  2. FortiTokens need to be removed from the mobile units.
  3. All FortiTokens need to be deleted from the FortiGate configuration.
  4. FortiTokens need to be reactivated and assigned to the users.
  5. Once FortiTokens are assigned, they need to be activated on the mobile unit by following this document:

FortiToken Mobile user instructions

 

Note: The policy for Migration of FortiToken Mobile is changing from 4th August 2025. The FortiToken Mobile licenses purchased after 4th August 2025 are not supported for migration unless it is an RMA. For more information, refer to this article: Technical Tip: FortiToken Mobile will no longer support License Transfer between different devices.

 

Related articles:

Technical Tip: Forti-Mobile token configuration in detail

Technical Tip: Migrating users and FortiTokens to another FortiGate/FortiAuthenticator

Technical Tip: FortiToken Mobile will no longer support License Transfer between different devices