FortiToken
FortiToken Mobile is an application for iOS or Android that acts like a hardware token but utilizes hardware the majority of users possess, a mobile phone.
mshahsavari
Staff
Staff
Article Id 196456

Description

 

This article describes Dial up Ipsec VPN with FortiToken and activation process.


Scope

 

FortiToken.

 

Solution

 

  1. Create a user definition with at least 6 characters.
  2. Go to System -> Config -> Advance and under email service enter an email and smtp server which could be :  smtp.fortinet.com.
  3. Enable authentication in front of the smtp user: enter the email address, the password and then apply.
  4. Go back to the user which has been created and enable email address and SMS.
  5. elect the country and the phone number.
  6. Enable two factor authentications.
  7. Select the Token and add the group.
  8. Select send activation code: a code is sent on the phone or email
  9. Use this code for activating the mobile FortiToken after installation.
  10. Add the user to the user group.
  11. Install the FortiToken mobile on the phone and then use a random username (test) with the activation code received via email or SMS.
  12. This links the FortiToken mobile to the FortiGate .
  13. This may take a few minutes for the token to be assigned to the user.
  14. Otherwise, thus shows as pending.
  15. Go to the FortiToken and make sure this is showing as assigned and not pending.
  16. The mobile generates a code that gives enough time to do the following process, a maximum 1 minute.
  17. Enter the credential on the phone within 1 minute.
  18. Before that enter: server ip/account will be the user created and password will be the user password with no space and Token generated key: for example, if the user password is 123456 and the generated code is 45324, enter 12345645324 which will be consider as password.
  19. Enter the group name and the pre-shared key from the phase 1 vpn.once turnt on the vpn, enter 12345645324 which includes the user password and the generated Token code.
  20. The setting on the phone can be done first.
  21. Enter the password with the token key to not run out of time with the token code. Remember the FortiToken has to show assigned and not pending.
  22. Add this group to the phase 1 VPN as well.