Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
bartman10
Contributor

FortiToken BROKEN IN 5.2

In 5.2 FortiToken users will get an error " Permission Denied (-455)" . All the FT and VPN debug logs look good... will say it' s working.. Known issue with 5.2... I don' t want to type it all over again but here' s my reply to a user in the FortiToken room. I had the same issue with my 300C' s.. A tech milled around asking for this and that log for an entire day. Next day he was out and I spoke with another guy. He checked 1-2 things then put me on hold for a sec... He came back and said this is A KNOWN ISSUE with 5.2!! The temp fix is to put the password and token # all in the password line with no spaces. It will work. So if my pass is " He8mycode!" and my token is showing 12345. Use " He8mycode!12345" as the password and it works. Said fix is slated for 5.2.1 Aug 15 2014. This is the 2nd glaring, in your face, you can' t miss it, firmware issue I' ve seen and I' ve only had FG for less than 1 year now! My 200D' s traffic stats are all messed up in every view. WAN interface shows BITS of traffic, and apps like YouTube show BITS and BYTES of traffic... WRONG.. I was told someone typed in the wrong network processor or something and it messed up all the stats... That has been broken for longer than I' ve had my 200D and only just got fixed in 5.0.8 and 5.2 so they say.. I really like FN products.. but their QA is freeken out to lunch.. how could you miss the traffic only logging bytes... when you first log into the GUI the first thing you see is WAN interface... did you not notice no traffic in your test? Did you test the FortiToken in 5.2? You could NOT have... it' s impossible.

300E x3, 200D, 140D, 94D, 90D x2, 80D, 40C, handful of 60E's.. starting to loose track.

Over 100 WiFi AP's and growing.

FAZ-200D

FAC-VM 2 node cluster

Friends don't let friends FWF!

300E x3, 200D, 140D, 94D, 90D x2, 80D, 40C, handful of 60E's.. starting to loose track. Over 100 WiFi AP's and growing. FAZ-200D FAC-VM 2 node cluster Friends don't let friends FWF!
3 REPLIES 3
TomS
New Contributor

Tokens are working for me in 5.2 (I' m only running 90Ds though). That said, I' m feeling much the same as you right now and I' m only 1 month in. I' ve got 2 open tickets which are being ignored and another issue sprung up today.
bartman10
Contributor

Tom.. I feel you.. but I have to say I still like the product and continue to deploy them at my global locations... They have some real WTF issues.. and I really can' t figure out WHY they don' t have a " Known issues" section available for us to freeken look at.. or WHY it takes support 1-2 days of goofing around to look at their own internal " Known Issues" and then tell me it' s a known issue... BUT.. with that said.. I still like the product.. Support does eventually find and fix some issues when I' ve had them... I think the rule of " don' t ever be the first to update" really applies here... Again.. they have some issues that kind of puzzle me for a company this size.. and coming from Cisco gear it seems a bit crazy... but after using them now for 6-7 months I still recommend them to people and like the product.. Side note.. I almost had tears in my eyes when they showed me " get" and " show" at the command line when in a sub section to show you the actual set values!... god.. how great! I' ve wanted that from Cisco for ever!

300E x3, 200D, 140D, 94D, 90D x2, 80D, 40C, handful of 60E's.. starting to loose track.

Over 100 WiFi AP's and growing.

FAZ-200D

FAC-VM 2 node cluster

Friends don't let friends FWF!

300E x3, 200D, 140D, 94D, 90D x2, 80D, 40C, handful of 60E's.. starting to loose track. Over 100 WiFi AP's and growing. FAZ-200D FAC-VM 2 node cluster Friends don't let friends FWF!
bartman10
Contributor

I meant to post I started with a 200D.. then upgraded to dual 300C in Active/Active, sent the 200D to my India location which FN said is fine and they will still support! NO ONE does that! Allow you to move devices between geo global locations! So now I have 300C- Active/Active Primary location 300C- Single, North China location 200D- Shipping to India location 40C- Small office in China.. Hate this thing.. don' t buy one.. to cut down and runs out of ram with default settings when you turn the damn thing on... 90D- Texas location Will be getting more for South China, Holland, South Africa, 2 US offices, and a couple more locations.. and about 40-50 FortiAP WiFi access points during the " initial test" deployment.. should have couple hundred+ in the next couple years.. Crazy to think..

300E x3, 200D, 140D, 94D, 90D x2, 80D, 40C, handful of 60E's.. starting to loose track.

Over 100 WiFi AP's and growing.

FAZ-200D

FAC-VM 2 node cluster

Friends don't let friends FWF!

300E x3, 200D, 140D, 94D, 90D x2, 80D, 40C, handful of 60E's.. starting to loose track. Over 100 WiFi AP's and growing. FAZ-200D FAC-VM 2 node cluster Friends don't let friends FWF!
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors