Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
guygox
New Contributor

Fortitoken

Hi, Since I updated my Fortinet 60C to v5.2.0,build0589 (GA), I have problem while using Fortitoken (Mobile). If I enter good credentials, it ask me to enter my Fortitoken Mobile code. Then I get never loggued : I only have a log in the Fortinet logs which says invalid credentials. Log Description SSL VPN login fail Log ID 39426 Message SSL user failed to logged in Raison sslvpn_login_unknown_user Any Idea why? Tanguy
4 REPLIES 4
bartman10
Contributor

I had the same issue with my 300C' s.. A tech milled around asking for this and that log for an entire day. Next day he was out and I spoke with another guy. He checked 1-2 things then put me on hold for a sec... He came back and said this is A KNOWN ISSUE with 5.2!! The temp fix is to put the password and token # all in the password line with no spaces. It will work. So if my pass is " He8mycode!" and my token is showing 12345. Use " He8mycode!12345" as the password and it works. Said fix is slated for 5.2.1 Aug 15 2014. This is the 2nd glaring, in your face, you can' t miss it, firmware issue I' ve seen and I' ve only had FG for less than 1 year now! My 200D' s traffic stats are all messed up in every view. WAN interface shows BITS of traffic, and apps like YouTube show BITS and BYTES of traffic... WRONG.. I was told someone typed in the wrong network processor or something and it messed up all the stats... That has been broken for longer than I' ve had my 200D and only just got fixed in 5.0.8 and 5.2 so they say.. I really like FN products.. but their QA is freeken out to lunch.. how could you miss the traffic only logging bytes... when you first log into the GUI the first thing you see is WAN interface... did you not notice no traffic in your test? Did you test the FortiToken in 5.2? You could NOT have... it' s impossible.

300E x3, 200D, 140D, 94D, 90D x2, 80D, 40C, handful of 60E's.. starting to loose track.

Over 100 WiFi AP's and growing.

FAZ-200D

FAC-VM 2 node cluster

Friends don't let friends FWF!

300E x3, 200D, 140D, 94D, 90D x2, 80D, 40C, handful of 60E's.. starting to loose track. Over 100 WiFi AP's and growing. FAZ-200D FAC-VM 2 node cluster Friends don't let friends FWF!
Dipen
New Contributor III

This is something how RSA SecureID works...Using Passcode instead of Password... :)

Ahead of the Threat. FCNSA v5 / FCNSP v5

Fortigate 1000C / 1000D / 1500D

 

Ahead of the Threat. FCNSA v5 / FCNSP v5 Fortigate 1000C / 1000D / 1500D
Sean_Toomey_FTNT

Hi Tanguy, Sorry to hear about your issue. I use FortiToken mobile for both administration and SSL VPN as it happens, and I' m on a FGT-100D running 5.2.0 and have no issues. So at the very least it isn' t a problem on 100% of installations. FortiOS 5.2.1 is right around the corner and should fix your issue based on bartman' s information. I will try to verify that internally as well. Cheers!
-- Sean Toomey, CISSP FCNSP Consulting Security Engineer (CSE) FORTINET— High Performance Network Security
neonbit
Valued Contributor

I' ve just tested this on my FGT VM running 5.2 and SSLVPN logins with Fortoken Mobile OTP are working correctly. Just to confirm guygox, if you browse to User & Device > FortiTokens, do you see your FTKMOB show up as ' Assigned' ?
Labels
Top Kudoed Authors