Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
RolandBaumgaertner72
Contributor III

Change to FG90G? FortiToken transfer?

Hey,

 

we have a quite a lot FGs in our network but sofar no G model, any bad experiences with this model? We are thinking to trade up a FG81E to 90G, comparing the specs it is quite a huge step but I would like to know if we can expect this hardware change as an easy one. For example we are testing with a 30G model and the updates are quite strange.

 

The only thing that bothers me right now is that in this location we have more than 30 user assigned with FortiToken.Sofar we never changed Tokens from one FG to another, as I have been told it should not be so hard but I would like to know if we later can keep the same tokens for the users.

 

Thanks for your information!

17 REPLIES 17
Toshi_Esumi

The problem with HA with the new FGT-bound FortiToken Mobile is when swap-over happens and the cause of the swap-over is not solved, a new token assignment/activation can't be done. You need to wait until the cause is resolved and get them swapped back to do that.
So in case you're planning HA, you better get FortiToken Cloud from now on.

Toshi

RolandBaumgaertner72
Contributor III

Hello,

 

I dont really understand what is it about the HA. We always have HA in our offices, so also in this case. Like one year ago when we started with FortiToken we asked Fortinet and they never mentioned that it is impossible to move FortiToken Licences. Because of that we started on the smaller unit since we still had to do an upgrade on our main FG cluster. We dont use FortiCloud Tokens, we tested it before but than we decided to take the old licences.

 

I dont really see the sense in purchasing again the Tokens, we are updating the firewalls so there should be not such a showstopper, no?

 

Thanks!

 

AEK

The KB doesn't mention that the tokens are transferable in case of trade-up neither (hardware refresh), in this case that would be nonsense I agree with you.

I hope Fortinet will review this change (or correct the KB if it is wrong) before Q3.

AEK
AEK
Toshi_Esumi

Smaller models like 90G wouldn't be a matter for this, but larger models like 1000F or above have options to get vdom licenses to add more than the default 10 vdoms to each device, like 5 more vdoms, 10 more, 50.... The vdom licenses have never been transferable even for tradeup deals. FTNT might be thinking to treat the FortiToken Mobile licenses in the same way.

Toshi

Toshi_Esumi

It's very ironic or funny if you think about this is about FortiToken "MOBILE" licenses no longer "movable".

Toshi

AEK
SuperUser
SuperUser

This also means who has 1000 tokens it's time to migrate them to FortiAuthenticator (or to FortiToken Cloud if it is used only by Fortinet Equipment)

AEK
AEK
Yurisk
SuperUser
SuperUser

Wow, that's kind of a big deal for us MSP/Integrator, as we have lots of clients which move FTMs between models, from our  managed VDOMs to their own hardware and vice versa, etc. quite a lot. 

I also didn't see any public announcement about that, thanks for investigating @Toshi_Esumi !

https://yurisk.info
https://yurisk.info
Toshi_Esumi
SuperUser
SuperUser

Originally @AEK found out the KB. Then, I contacted the KB owner and our SE from FTNT to clarify. They apparently worked together behind the scene contacting the product group and updated the KB.

Toshi

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors