Description | This article describes recommendations when assigning a new user in FortiCloud Portal fails due to reaching quota limit while there are still available tokens in the pool. |
Scope | FortiGate - FortiToken Cloud |
Solution |
Check if the license is active by selecting the 'License' option on the FortiCloud portal:
After confirming the license is active, make sure FortiGate has the sync with FortiToken-Cloud portal enabled under global settings:
config system global set fortitoken-cloud enable end
The next step is to check if the sync is working and view the status of the licenses on the FortiGate:
execute fortitoken-cloud show
One logical step is to run the FortiToken-Cloud debug on the FortiGate and then to assign a token to a user account similar to the example below:
diag fortitoken-cloud debug enable diagnose debug enable
Adding a user:
execute fortitoken-cloud new <username> <remote or local> <vdom>
Example of a possible error:
If the server status is good and the debug is only showing that the quota is reached while there are more available on the same license, it is safe to assume there is a possible issue on the FortiToken-Cloud portal:
One possible cause is the realm configuration on the portal where 'shared-quota setting' may have been disabled, which means it is possible a lower number of tokens was assigned to the FortiGate realm. For more information regarding realm settings on the FortiToken-Cloud portal, see Manage realms. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.