Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
AEK
SuperUser
SuperUser

FortiAuthenticator offline authentication token issue

Hello
We have FAC version 6.4.9, with Windows agent version 4.3, 2FA with FortiToken mobile.

While online authentication works just fine, sometimes some users fail to login when they open a Windows session in offline mode (disconnected from the Corp network). The error shown on Windows login screen is user and password incorrect with "Offline Tokens: None Available".

As this behavior appears from time to time it becomes a real issue, especially when the user is offsite as we can't assist him.

Any hint to fix or troubleshoot the issue would be appreciated.

AEK
AEK
6 REPLIES 6
rbraha
Staff
Staff

Hi @AEK 

In case of this user using offline token , l would suggest to delete offline token for this user from FAC  Agent- Simulation Tab there is an option to delete these file of offline token downloaded on this PC.

Then the user need to login on local network first ,an new list of offline token will be downloaded automatically from FAC to end user PC and then you can test it again to login using offline token.

AEK

Hello Braha, and thanks for your feedback.

 

Actually we could fix the issue in a simple way just by disabling the offline authentication on the Windows agent, then enabling it again.

Actually this is a workaround and it works, however the problem is that when user is offsite and can't connect due to this issue then it is difficult to assist him and sometimes not even possible, so we are trying to find a good solution that will prevent such behavior to happen once for all.

 

Meanwhile and besides, any quick & secure workaround is welcome. I'm think about enabling emergency code (or other good temporary solution), however I'm wondering how secure is this solution comparing with TOTP token and what is the best practice for it.

 

Any further advice would be appreciated.

AEK
AEK
rbraha

Hi,

By default this file is save in the following path: C:\Program Files\Fortinet\FortiAuthenticator Agent\Offline\  and its valid for 7 days but can be increased on FAC side but for some reason when user authenticate using one  token and which is compared with this list it may fail, so this token code it may be not in this list.

That's why l asked to delete this file and logout/login from PC in a local network will download automatically another list from FAC.

 

Regarding Emergency token it is secure but it can only used on cases when user does not have access to his phone but l think cannot be used every day.

AEK

Thanks Braha for your valuable advice.

AEK
AEK
Debbie_FTNT

To clarify a bit on Emergency token:

- this can be enabled in a user account on FortiAuthenticator

- this sends an Email or SMS one time (with a code) if the user reports the token lost or otherwise unusable

- the Emergency token is automatically disabled after one use, so it cannot be abused to get around the actual token requirement

+++ Divide by Cucumber Error. Please Reinstall Universe and Reboot +++
AEK
SuperUser
SuperUser

We finally found that the issue was caused by a couple of misconfigurations:

  • Upgraded the Windows agent from 4.3 to 5.3
  • Some users had their mobile phone not synchronized with NTP server -> This one has been fixed just by enabling auto date/time on the phone
  • One user had the character "รง" in his username. TAC support said it not supported for offline token -> We had to migrate his domain account to a new one without "รง" character
AEK
AEK
Announcements

Select Forum Responses to become Knowledge Articles!

Select the โ€œNominate to Knowledge Baseโ€ button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors