FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
mflamingos
Staff
Staff
Article Id 194933

Description

 

This article explains how to transfer a FortiToken Mobile to a new phone when a user gets a new device or if their phone is lost or stolen. Additionally, it covers the process of reassigning a FortiToken previously assigned to one user, enabling it to be reused by another user.
 
Scope
 
FortiToken Mobile.


Solution

 

The following steps will permit the transfer of the mobile token to the new phone:
 
For Local User:
  1. Go to User & Authentication -> User Definition and select the user who needs to transfer the token and select 'Edit'.
  2. Disable Two-factor Authentication and select OK. The token will be removed from the user's Two-factor authentication column. The user will also be removed from the token's User column, under User & Authentication -> FortiTokens.
  3. Edit the user again and re-enable 'Two-factor Authentication' with FortiToken as shown below. 
  4. After selecting 'OK', the user should receive an email with the activation code.
 
axscdc.PNG

 

asdad.PNG

 

  1. Check again under User & Authentication -> FortiTokens, the status should now be 'pending'.

 

For Administrator: 

  1. Log in to FortiGate with a super admin account and modify the desired admin account. Browse to System -> Administrators and edit the admin user, then disable the Two Factor authentication.

 

already assigned user.png

 

  1. Confirm that it has been removed. The token will be removed from the admin user's Two-factor authentication column as well as from the token's User column, under User & Authentication -> FortiTokens.
  2. Under System -> Administrators, edit the admin user and re-enable the Two-factor authentication.

 disable2fa.png

 

enabled2fa.png 

     5. Enter the mandatory information and save by selecting 'OK'. It should send an email with a QR code.  If an error message is seen, run the following commands on the FortiGate unit:

 

execute fortitoken-mobile provision <serial-number>
execute fortitoken-mobile renew <serial-number>

 

If an activation code email is not being sent, refer to this article to collect debugs: 

Troubleshooting Tip: Email alert

 

Related articles:

Deactivating a FortiToken - FortiToken documentation.

Configuring FortiTokens - FortiToken documentation.

Technical Tip: FortiGate is not sending a FortiToken activation code

Troubleshooting Tip: Get FortiToken Mobile activation code when activation email is not received

Technical Tip: FortiToken basic troubleshooting