Hi all,
since a few months we use 2-factor authentication with FortiToken (Mobile and Hardware) for some Firewall-Policys, which works like a charm. Now we decided, to use the same authentication for a dialup IPSec VPN on the same Fortigate. Basically it works with FortiClient 5.2.4, but some users are unable to use a tokencode older than 15 seconds! For example, when you open the app (FortiToken Mobile) and the current token is valid for the next 30 seconds, no VPN-connetion is possible. So you have to wait 30 seconds until the next token is showing and then login is smoothly. Any ideas? Thank you...
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Perhaps it's a problem with the token and the drift? Probably worthwhile re-syncing the tokens to be sure.
This command will re-sync a single token:
execute fortitoken sync <serial_number> <code> <next code>
To list the drift for all tokens use this command:
diag fortitoken drift
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1710 | |
1093 | |
752 | |
446 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.