Hello
We have FAC version 6.4.9, with Windows agent version 4.3, 2FA with FortiToken mobile.
While online authentication works just fine, sometimes some users fail to login when they open a Windows session in offline mode (disconnected from the Corp network). The error shown on Windows login screen is user and password incorrect with "Offline Tokens: None Available".
As this behavior appears from time to time it becomes a real issue, especially when the user is offsite as we can't assist him.
Any hint to fix or troubleshoot the issue would be appreciated.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi @AEK
In case of this user using offline token , l would suggest to delete offline token for this user from FAC Agent- Simulation Tab there is an option to delete these file of offline token downloaded on this PC.
Then the user need to login on local network first ,an new list of offline token will be downloaded automatically from FAC to end user PC and then you can test it again to login using offline token.
Hello Braha, and thanks for your feedback.
Actually we could fix the issue in a simple way just by disabling the offline authentication on the Windows agent, then enabling it again.
Actually this is a workaround and it works, however the problem is that when user is offsite and can't connect due to this issue then it is difficult to assist him and sometimes not even possible, so we are trying to find a good solution that will prevent such behavior to happen once for all.
Meanwhile and besides, any quick & secure workaround is welcome. I'm think about enabling emergency code (or other good temporary solution), however I'm wondering how secure is this solution comparing with TOTP token and what is the best practice for it.
Any further advice would be appreciated.
Hi,
By default this file is save in the following path: C:\Program Files\Fortinet\FortiAuthenticator Agent\Offline\ and its valid for 7 days but can be increased on FAC side but for some reason when user authenticate using one token and which is compared with this list it may fail, so this token code it may be not in this list.
That's why l asked to delete this file and logout/login from PC in a local network will download automatically another list from FAC.
Regarding Emergency token it is secure but it can only used on cases when user does not have access to his phone but l think cannot be used every day.
Thanks Braha for your valuable advice.
To clarify a bit on Emergency token:
- this can be enabled in a user account on FortiAuthenticator
- this sends an Email or SMS one time (with a code) if the user reports the token lost or otherwise unusable
- the Emergency token is automatically disabled after one use, so it cannot be abused to get around the actual token requirement
We finally found that the issue was caused by a couple of misconfigurations:
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1662 | |
1077 | |
752 | |
446 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.