Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
RolandBaumgaertner72
Contributor III

FortiToken Error with IPSec, SSL VPN works fine???

Hello,

 

since we cant use SSL VPN with the G model we are trying to move to remote IPSec.

We are testing first with the IT department. Last week, everything was fine, no problems connecting to IPSec.

But yesterday one of our technician was not able to connect. The problem was the Token, while connecting he was asked to put the token and he got denied. He tried like 2 times and than switched to SSL VPN where the Token was working the first time connecting.

 

That makes us really uncomfortable thinking about switching all users to IPSec which we have to do some time soon.

I checked the Log files and I dont get an idea about the failure. First it seems OK:
Action negotiate
Status success
Result XAUTH authentication successful

An than the last Log is: Action delete_phase1_sa

The thing is that there is no failure with FortiToken since it works fine with SSL VPN so I dont know where to look for a possible failure.

Thanks!

1 REPLY 1
AEK
SuperUser
SuperUser

Hi Roland

Are you using FortiAuthenticator or the user/token is directly on FGT?

But anyway first thing I suggest to do is to disable token authentication for the user and try again, just to see if the issue is actually caused by the 2FA or not.

AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors