Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
SkeletonManGabe
New Contributor III

FortiCloud and FortiAuthenticator Mobile Tokens

Good afternoon. I'm in need of ordering more tokens for our internal Fortiauthenticator environment and I was looking to order Mobile tokens since they are perpetual. I'm trying to determine, if I purchase and import mobile tokens into my internal fortiauthenticator environment, if I ever choose to move to "FortiCloud", will those mobile tokens be able to transfer to that?

 

Also, is the FortiCloud option usable for the internal FAC agents I have installed on all my servers, workstations and network equipment? The reason I ask is because of remote workers. Right now, my remote workers are exempt users on their devices because offline tokens aren't suitable for long-term at home users. I could certainly expose my Fortiauthenticator to the internet, just not sure if I want to do that. Would I be able to specify and internal fortiauthenticator device and the cloud url to my clients so they could use either one depending on where their token is stored? Or is this solution just not that robust? 

 

Thanks in advance for answering my questions, I do appreciate it. 

1 Solution
gfleming
Staff
Staff

FortiToken Cloud is just for hosting Tokens—it does not authenticate users. You would still use your internal FAC server to integrate with it. And no you cannot use FortiTokens in FAC and transfer them to FortiToken Cloud. They are completely different licensing mechanisms.

 

You can certainly expose your FAC to the internet. You only need to expose HTTPS/port 443. It's the recommended way to provide secure MFA to all of your users regardless of where they are.

Cheers,
Graham

View solution in original post

1 REPLY 1
gfleming
Staff
Staff

FortiToken Cloud is just for hosting Tokens—it does not authenticate users. You would still use your internal FAC server to integrate with it. And no you cannot use FortiTokens in FAC and transfer them to FortiToken Cloud. They are completely different licensing mechanisms.

 

You can certainly expose your FAC to the internet. You only need to expose HTTPS/port 443. It's the recommended way to provide secure MFA to all of your users regardless of where they are.

Cheers,
Graham
Labels
Top Kudoed Authors