Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
zkonrad001
New Contributor

Fortiauthenticator at PC login screen "incorrect username or Password"

Having an issue with my employees getting logged in.

Its only happening to random computers and everyday its someone else's.

Its even happened to me as an administrator.

We use Fortinet 2 factor authentication and have a Fortigate firewall.

The issue we are having, is that when an employee tries to log in, they get an error for "incorrect username or password".

 

I've tried changing passwords, removing the Fortitoken and user from the Fortiauthenticator and then re-adding them, and tried different users to log in.  So it doesn't seam like its the user, but actually the PC.  

We are currently using Fortiauthenticator v3.8

 

When we remove the Fortiauthenticator from the computer, the user is able to log in.

Right now its removed from about 20% of our company PC's just so we can have employees logged in and working.

3 REPLIES 3
warshad
Staff
Staff

Are you using Fortigate or Fortiauthenticator for 2FA? What is FAC version?

 

 

Waqas Arshad
Fortinet
zkonrad001

So the issue is with my 2FA.  

Our users have to sign in with:

Username, Password, and fortitoken 6 digit authentication (we use the keyfobs)

Version is 3.8

Debbie_FTNT

Hey zkonrad,

thanks for providing the details.

The Windows Agent writes log files you can consult to determine if the issue is with the user credentials for some reason, or the token code. You can find the logs in the installation directory (possibly one of the folders within the installation directory).

In addition, you can check logs on your FortiAuthenticator when the issue happens - there should be a web service/API log for the user login (the Agent checks user credentials via API against FAC), and probably another log for successful or failed token authentication.

Those should give you some idea if FortiAuthenticator randomly has issues with the token code (in which case resyncing the token could help) or with the actual user credentials (in which case there should be some further details as to why user credentials failed, such as unable to contact AD server or an error code)

Based on what you find in the logs, you can then focus your troubleshooting or reach out to the FortiAuthenticator team via a support ticket; Agent support is included in the FortiAuthenticator support.

+++ Divide by Cucumber Error. Please Reinstall Universe and Reboot +++
Labels
Top Kudoed Authors