Fortinet white logo
Fortinet white logo

Admin Guide

26.2.0

FTM

FTM

To configure the FTM settings of a realm:

  1. Click Settings>Realm.

  2. Select the realm.

  3. Click FTM.

  4. Set or update the parameters as described in the following table.

  5. Click Apply Changes.

Parameter

Default value

Settings
Enable Push Enable or disable push notification.

Notification Method

Select either of the following:

  • Email—Token activation/transfer codes are sent to users' email addresses.
  • SMS—Token activation/transfer codes are sent by SMS to users' mobile phone numbers.

Note: When Notification Method is set to SMS, make sure that the users' mobile phone numbers in the system are valid. Otherwise, you will get an error when requesting a new token for users on the Users page. See Users.

Note: FIC deducts one credit from your credit balance for every 250 SMS messages it sends to deliver OTPs. You may experience some problem sending OTPs by SMS when your credit balance is low, and you will get an error message when trying to send an OTP if there is no credit remaining on your account. In both cases, we strongly recommend that you purchase more credits before attempting to use this feature.

App PIN Required

Enable or disable app pin requirement.

  • Disabled (default)—No app PIN is required.
  • Enable—If enabled, you must select a PIN Length and PIN Required Mode, as described below.

PIN Length

Select one of the following:

  • 4
  • 6 (default)
  • 8

Note: PIN length refers to the number of digits contained in an app PIN.

PIN Required Type

Select either of the following:

  • Anytime—App PIN is required all the time.
  • Unlock—If selected, end-users must have a PIN either on their device or FTM app to access FIC. If an end user has a PIN on the device, FIC won't ask for a PIN when using FTM; if an end user does not have a PIN on the device, FIC will ask for a PIN to use FTM.

OTP Algorithm

Select a One-Time Password algorithm.

Note: FIC supports Time-Based One-Time Password (TOTP) only; no action is needed.

OTP Time Step

Select the duration for which a generated OTP code remains valid,

Select either of the following:

  • 30 (default)
  • 60

Note:OTP Time Step refers to the frequency in which FTM token codes are updated. For example, FIC will update FTM token codes once every 30 seconds when OTP Time Step is set to 30.

OTP Validation Window

Select he number of time steps the validation server takes to validate OTPs.

Upon receiving an OTP from a client, the validation server computes the OTP using the shared secret key and its current timestamp (not the one used by the client) and compares the OTPs: if the OTPs are generated within the same time step, they match and the validation is successful.

OTP Display Length

Select either of the following:

  • 6 (default)
  • 8

Note: OTP Display Length refers to the number of digits contained in a token activation/transfer code.

Activation Expiration Time

Specify the length of time token activation codes remain valid. Valid values range from 1 to 336 hours. The default is 72 hours.

Note: An FTM Token code must be activated within the set Activation Expiration Time. Otherwise, it will expire and you must request a new token.

Templates

Token Activation Email

An email template for FIC to send token activation notifications to your end-users.

Token Transfer Email

An email template for FIC to send token transfer notifications to your end-users.

Token Activation SMS

An SMS template for FIC to send token activation notifications to your end-users.

Token Transfer SMS

An SMS template for FIC to send token transfer notifications to your end-users.

FTM

FTM

To configure the FTM settings of a realm:

  1. Click Settings>Realm.

  2. Select the realm.

  3. Click FTM.

  4. Set or update the parameters as described in the following table.

  5. Click Apply Changes.

Parameter

Default value

Settings
Enable Push Enable or disable push notification.

Notification Method

Select either of the following:

  • Email—Token activation/transfer codes are sent to users' email addresses.
  • SMS—Token activation/transfer codes are sent by SMS to users' mobile phone numbers.

Note: When Notification Method is set to SMS, make sure that the users' mobile phone numbers in the system are valid. Otherwise, you will get an error when requesting a new token for users on the Users page. See Users.

Note: FIC deducts one credit from your credit balance for every 250 SMS messages it sends to deliver OTPs. You may experience some problem sending OTPs by SMS when your credit balance is low, and you will get an error message when trying to send an OTP if there is no credit remaining on your account. In both cases, we strongly recommend that you purchase more credits before attempting to use this feature.

App PIN Required

Enable or disable app pin requirement.

  • Disabled (default)—No app PIN is required.
  • Enable—If enabled, you must select a PIN Length and PIN Required Mode, as described below.

PIN Length

Select one of the following:

  • 4
  • 6 (default)
  • 8

Note: PIN length refers to the number of digits contained in an app PIN.

PIN Required Type

Select either of the following:

  • Anytime—App PIN is required all the time.
  • Unlock—If selected, end-users must have a PIN either on their device or FTM app to access FIC. If an end user has a PIN on the device, FIC won't ask for a PIN when using FTM; if an end user does not have a PIN on the device, FIC will ask for a PIN to use FTM.

OTP Algorithm

Select a One-Time Password algorithm.

Note: FIC supports Time-Based One-Time Password (TOTP) only; no action is needed.

OTP Time Step

Select the duration for which a generated OTP code remains valid,

Select either of the following:

  • 30 (default)
  • 60

Note:OTP Time Step refers to the frequency in which FTM token codes are updated. For example, FIC will update FTM token codes once every 30 seconds when OTP Time Step is set to 30.

OTP Validation Window

Select he number of time steps the validation server takes to validate OTPs.

Upon receiving an OTP from a client, the validation server computes the OTP using the shared secret key and its current timestamp (not the one used by the client) and compares the OTPs: if the OTPs are generated within the same time step, they match and the validation is successful.

OTP Display Length

Select either of the following:

  • 6 (default)
  • 8

Note: OTP Display Length refers to the number of digits contained in a token activation/transfer code.

Activation Expiration Time

Specify the length of time token activation codes remain valid. Valid values range from 1 to 336 hours. The default is 72 hours.

Note: An FTM Token code must be activated within the set Activation Expiration Time. Otherwise, it will expire and you must request a new token.

Templates

Token Activation Email

An email template for FIC to send token activation notifications to your end-users.

Token Transfer Email

An email template for FIC to send token transfer notifications to your end-users.

Token Activation SMS

An SMS template for FIC to send token activation notifications to your end-users.

Token Transfer SMS

An SMS template for FIC to send token transfer notifications to your end-users.