Fortinet white logo
Fortinet white logo

Diagnosing FortiToken on FortiGate

Diagnosing FortiToken on FortiGate

The following diagnose command will show a list of FortiTokens, with drift and status:

diagnose fortitoken info

FORTITOKEN        DRIFT  STATUS
FTK200XXXXXXXXXX  0      new
FTKMOBXXXXXXXXXX  0      new

Total activated token: 0
Total global activated token: 0

Token server status: reachable
Status outputs:
  • new

    Newly added to FortiGate and not assigned to a user.

  • active

    Assigned to a user. This output is for FortiToken-210 only.

  • provisioned

    User has activated their token and it is assigned to them. This output is for FortiToken Mobile only.

  • provision timeout

    The administrator assigned the token to the user, but the user did not activate the token within the timeout period. The token must be re-provisioned to the user.

  • token already activated, and seed won't be returned

    This token has been added, removed, and re-added to the FortiGate. To transfer hardware tokens from one FortiGate or FortiAuthenticator device to another, visit the Fortinet Support website to open a technical support ticket to reset the activation flag. See Creating tickets in the FortiCare guide.

    Note that FortiToken Mobile tokens and licenses are not transferable between devices (except for RMA). However you can easily and transparently migrate tokens from the device to FortiIdentity Cloud without having to re-assign tokens to end users. See Migrate FTM tokens to FortiIdentity Cloud in the FortiIdentity Cloud Admin Guide for details on how to do this.

  • activation error (token not exist in FortiGuard)

    There is no contact to the FortiGuard server. In the event of this status, visit the Fortinet Support website.

    When contacting customer support, you must provide the FortiToken serial number as well as the FortiGate or FortiAuthenticator serial number to which the token is assigned.

Diagnosing FortiToken on FortiGate

Diagnosing FortiToken on FortiGate

The following diagnose command will show a list of FortiTokens, with drift and status:

diagnose fortitoken info

FORTITOKEN        DRIFT  STATUS
FTK200XXXXXXXXXX  0      new
FTKMOBXXXXXXXXXX  0      new

Total activated token: 0
Total global activated token: 0

Token server status: reachable
Status outputs:
  • new

    Newly added to FortiGate and not assigned to a user.

  • active

    Assigned to a user. This output is for FortiToken-210 only.

  • provisioned

    User has activated their token and it is assigned to them. This output is for FortiToken Mobile only.

  • provision timeout

    The administrator assigned the token to the user, but the user did not activate the token within the timeout period. The token must be re-provisioned to the user.

  • token already activated, and seed won't be returned

    This token has been added, removed, and re-added to the FortiGate. To transfer hardware tokens from one FortiGate or FortiAuthenticator device to another, visit the Fortinet Support website to open a technical support ticket to reset the activation flag. See Creating tickets in the FortiCare guide.

    Note that FortiToken Mobile tokens and licenses are not transferable between devices (except for RMA). However you can easily and transparently migrate tokens from the device to FortiIdentity Cloud without having to re-assign tokens to end users. See Migrate FTM tokens to FortiIdentity Cloud in the FortiIdentity Cloud Admin Guide for details on how to do this.

  • activation error (token not exist in FortiGuard)

    There is no contact to the FortiGuard server. In the event of this status, visit the Fortinet Support website.

    When contacting customer support, you must provide the FortiToken serial number as well as the FortiGate or FortiAuthenticator serial number to which the token is assigned.