Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
krauboti
New Contributor II

SSL VPN 2FA email token/code not issued on first login attempt

Hi,

 

We are using two factor authorization with email token/code on our ssl vpn portal. Every time we create new users, they need to try login two times before email token is issued on the second try. Anyone have a solution/experience for this?

 

Thanks.  

5 REPLIES 5
hbac
Staff
Staff

Hi @krauboti,

 

Is it a local user on the firewall or LDAP/RADIUS user? Which FortiOS version are you using?

 

Regards, 

krauboti
New Contributor II

Hi @hbac,

 

Local users on the firewall, using FortiOS v7.2.3 build1262 on FGT40

mle2802
Staff
Staff

Hi @krauboti,
Can you please run the following command when tried to log in the first time:

diag debug reset
diag debug enable
diag debug console timestamp enable
diag debug application alertmail -1
diag debug application fnbamd -1 
diag debug en 

Regards,
Minh

krauboti
New Contributor II

Hi @mle2802,

 

Thank you for the assistance and tips. It looks like the problem might be at the smtp relay server (O365). Firewall creates the code every time but fails to connect to the server when sending email within a certain time period then next time connects and sends email with success. Will look into settings in O365.

 

Thanks again. 

krauboti
New Contributor II

It looks like the FGT fails to resolve the FQDN smtp.office365.com sometimes so the solution was to use the IP address instead. No problems with connecting to the smtp relay server yet. 

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Resolving-Inconsistency-in-Connecting-to-s...

 

Thanks for all the support. 

Labels
Top Kudoed Authors