Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
RolandBaumgaertner72
Contributor III

Moving FortiTokens to new FG Cluster

Hello,

 

we are preparing in one office the change from FG81E cluster to FG90F cluster. We have actual 50 One Time Forti Tokens assigned to 50 SSL VPN /IPsec LDAP Users.

 

As I understand I have to open a Ticket so that the CS team can move them to the new serials, correct?

 

Is there any chance to keep users with the old Tokens, like copying them in the config file or do I have to create them from LDAP again and assign them a new token? It could be difficult because I dont think that moving Fortitokens can be done in hours so maybe we have to let them x days without 2MFA.

 

Any suggestions to do this the best possible way?

 

Thanks!

 

2 REPLIES 2
shikhakolekar

Hello @RolandBaumgaertner72 , 

 

Please take a look at this article which explains migration of Hardware and Mobile FortiTokens to a new FortiGate.
https://community.fortinet.com/t5/FortiAuthenticator/Technical-Tip-Migrating-users-and-FortiTokens-t...

If you have a migration window planned, you can have the case raised along with CS with timeframe to move the tokens to the new box. Please note that for mobile tokens, they need to be activated in the app again. 

 

If you have found a solution, please like and accept it to make it easily accessible to others.

Toshi_Esumi
SuperUser
SuperUser

We originally tried copying the "config user fortitoken" entirely to a new FGT when the customer's VDOM was moved. Of course, we still had to get the license transferred to the new FGT by the CS, first.

But the "set reg-id" line seemed to include not only the client information but also something related to the FGT itself. Then the token auth failed when the same user tried.
So now we're going through the token activation process again for each user after activating the transferred license at their vdoms on the new FGTs.

One thing you need to expect during the transfer by CS is when you open a ticket, they need to confirm/get an approval from the master user of your account for the transfer via email. In our case, 
the master user email address is our group email address, which I'm a member of.
So I can provide the approval to them by myself before the maintenance. Then I call in the support during or after the vdom migration maintenance is done.

Toshi

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors