FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
candawi
Staff
Staff
Article Id 255898
Description

 

This article shows one of the possible solutions for a scenario where the hardware Token has a 'Pending' status in FortiGate -> User & Authentication -> FortiTokens and the error: 'Token server status : unreachable' appears under the command: 'diag fortitoken info' appears.

 

Scope

 

FortiGate.

 

Solution

 

Sample errors seen in FortiGate:

 

Picture1.png

 

Picture2.png

 

Turn on activation debugging by executing the commands below:

 

diagnose debug reset

diagnose debug console timestamp enable 

diagnose debug application forticldd 255

diagnose debug enable 

diagnose debug info

 

If the output below is visible, where 'Too many tasks in queue: 10', proceed with killing the forticldd process by executing the command below:

 

# fnsysctl killall forticldd

 

Run the 'diagnose fortitoken info' command and see if the Token server status is now reachable. 

 

Picture4.png

 

If it is reachable, proceed by selecting 'Refresh' -> User & Authentication -> FortiTokens. After a short time, the hard Token will now be in 'Available' status from 'Pending'.

 

Picture5.png

 

Related article:

Technical Tip: FortiToken basic troubleshooting