| Description |
This article describes how to resolve the issue with assigning FortiTokens after a firmware upgrade for FortiGate with HA setup. |
| Scope |
FortiGate. |
| Solution |
During the process of FortiGate HA upgrade, a failover will be performed. If the FortiGate HA cluster comes back online after the upgrade, but assigning FortiToken Mobile to new users returns with 'No valid token found' error, follow steps below:
Run below FortiToken debug while attempting to assign a token to the user.
diagnose fortitoken debug enable diagnose debug enable
If the error shows a similar message as '"error_message":"token does not belong to product"', verify the serial number of the current running primary unit and check if the FortiToken Mobile license is registered under the same serial number.
Run the following command to check the HA status and check which is the current primary and secondary unit:
get system ha status
To check the FortiToken Mobile license registration, log in to the Fortinet Support portal and check the license details of the devices under Asset Management.
If the FortiToken Mobile license is found registered under the current secondary unit serial number, either of the following options can be performed:
Related article: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.