Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
unknown1020
New Contributor III

problems with fortitoken

Good morning friends, a question.
I have changed equipment fortigate because the previous one was defective. When making the change, problems with fortitokens were validated. When the user has a fortitoken assigned, they cannot enter the VPN and on the other hand, users who do not have a normal token assigned can connect. Can you help me with this problem.

8 REPLIES 8
Toshi_Esumi
SuperUser
SuperUser

First, have you gotten the token licenses transferred from the defecitve one to the new RMA replacement? It must be automatic but you can check if they're still there at the support site, Asset page.
If they're there, you need to reactivate the token license at the new unit. Then unfortunately all users need to go through the token activation process with the new unit again. I don't think there is a way around (hoping someone says "You're wrong!").

 

Toshi

unknown1020

Hello, yes, the license has already been transferred from the old device to the new fortigate.

Then would I have to upload the fortitoken license to the new fortigate again?

Toshi_Esumi

Yes. You don't see all tokens except the free demo tokens under User&Authentication->FortiTokens, right? If not there, you can't use them.

unknown1020

If you see all the fortiokens, they just seem to be corrupted. Since users with the token enabled cannot connect to the VPN client. Do you have any KB?

Toshi_Esumi

If you're seeing "Error" status in GUI or "set status lock" in CLI for some tokens, what you need to do is to delete those tokens first, then re-apply the license to clear them. It wouldn't affect to working ones.
That's what we were told by TAC when we had that problems, and it worked.

 

Toshi

unknown1020

Toshi_Esumi

We never looked up any KB. Just opened a ticket at TAC and that's what we were told to do. It was quite intuitive as well for both deleting indivitual tokens (select and hit "Delete" button) and re-applying the license ("Create New" button).

Toshi_Esumi

ok. @hbac showed the KB describing the process of deleting/reactivating token in another thread today. It describes the step but no GUI references.
https://community.fortinet.com/t5/FortiGate/Technical-Note-Fix-Licensed-Mobile-Token-with-Error-Lock...

And this is the thread if you're interested.
https://community.fortinet.com/t5/Support-Forum/Unable-to-reactivate-a-mobile-Fortitoken/m-p/298042#...


Toshi

Labels
Top Kudoed Authors