Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Avim8686
New Contributor

Unable to send SMS using default Fortiguard SMS Messaging Service

Since this morning we are unable to use SMS authentication with msgctrl1.fortinet.com.

 

We've opened a support ticket but no issue has been identified , they are stating it's most likely on the fortinet side as we clearly see communications between our FortiAuthenticator (version 6.1.2) and the msgctrl1.fortinet.com URL on port 443 (full tcp handshake).

This was working for months and stopped working overnight with no configuration change or change in the environment. 

 

Anybody have any idea?

4 REPLIES 4
Avim8686
New Contributor

It seems like this was a problem on the Fortinet side , issue seems to be resolved just got spammed with a bunch of test SMS in the backlog.

xsilver_FTNT
Staff
Staff

Even FortiGuard Message Centers do use actual telco providers to deliver messages. So possible bottleneck could be anywhere. On FortiGuard, on mobile service provider for your location, their infrastructure .. anywhere.

Need to note that SMS is usually service without delivery guarantee.

If you use those SMS for example for 2FA token codes delivery, then I would suggest to consider other options like physical tokens, mobile tokens or cloud based tokens. They even might be cheaper in long term then SMS messages.

Alternatively you can configure quite a variety of 3rd party SMS Gateways in FortiAuthenticator, so it can deliver "SMS" for example to defined SMTP .. and so you'll get your token to your email via your private email server, free of charge, for example.

But for 2FA I personally really like mobile/cloud tokens and PUSH notifications. Simple, fast solution and comfy to use.

Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff

Yurisk
SuperUser
SuperUser

My (subjective - I work at telco) opinion - if to use SMS at all, then use local to the sending device SMS GAteway/Provider/telco, not the one from the Fortinet. I see SMS via Fortiguard as a means of free trial/pilot for the SMS MFA, after which you should switch to more adjacent and reliable SMS provider.  In locations where I cannot get local SMS gateway and Fortitoken is not an option, I prefer to use email as MFA with increased timeout for reliability. 

Yuri Slobodyanyuk
Yuri Slobodyanyuk
asharsick
New Contributor

thank you guys for answers. Are you services expensive?

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors