Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
idris
New Contributor

FortiClient VPN sends Token code but no Token field displayed until sometime later......

Hi, 

 

Hope someone can help. I am using FortiClient VPN have tried versions 6 to 7. I enter my login details and receive a token code, but no Token field is displayed immediately to enter the Token Code, after some time the Token field is displayed but when I enter the token code I see an error message  'Permission Denied. (-455).

 

Does anyone know why the Token filed is not being displayed immediately ?

 

Thanks

2 REPLIES 2
Kush_Patel
Staff
Staff

For  -455 code, it might be a problem with bad account or bad password. 

 

you can even try to increase the timeout for two factor settings on FGT:

# config system global

set two-factor-email-expiry <in s>

set remoteauthtimeout <1-300s>

 

At what percenatge you are getting the error ?

 

srajeswaran
Staff
Staff

Can you confirm where is the authentication configured? Is it on a Fortiauthenticator/radius server?
The OTP field is displayed after the initial user authentication is completed, what might be happening is the authentication is getting delayed due to network issue/latency or CPU/memory issue on the authentication device .

Since OTP is entered late, the authenticator device session is timedout before OTP is received and results in permission denied error.

For now you can try increasing the OTP expiry timers as suggested in following article

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-SSL-VPN-and-two-factor-expiry-timers...

Then check if there are any network issues/delays or CPU/Memory issues on authenticator device.

Regards,

Suraj

- Have you found a solution? Then give your helper a "Kudos" and mark the solution.

Labels
Top Kudoed Authors