Diagnosing FortiToken on FortiGate
The following diagnose command will show a list of FortiTokens, with drift and status:
diagnose fortitoken info
FORTITOKEN DRIFT STATUS FTK200XXXXXXXXXX 0 new FTKMOBXXXXXXXXXX 0 new Total activated token: 0 Total global activated token: 0 Token server status: reachable
Status outputs:
newNewly added to FortiGate and not assigned to a user.
activeAssigned to a user. This output is for FortiToken-210 only.
provisionedUser has activated their token and it is assigned to them. This output is for FortiToken Mobile only.
provision timeoutThe administrator assigned the token to the user, but the user did not activate the token within the timeout period. The token must be re-provisioned to the user.
-
token already activated, and seed won't be returnedThis token has been added, removed, and re-added to the FortiGate. To transfer hardware tokens from one FortiGate or FortiAuthenticator device to another, visit the Fortinet Support website to open a technical support ticket to reset the activation flag. See Creating tickets in the FortiCare guide.
Note that FortiToken Mobile tokens and licenses are not transferable between devices (except for RMA). However you can easily and transparently migrate tokens from the device to FortiIdentity Cloud without having to re-assign tokens to end users. See Migrate FTM tokens to FortiIdentity Cloud in the FortiIdentity Cloud Admin Guide for details on how to do this.
activation error (token not exist in FortiGuard)There is no contact to the FortiGuard server. In the event of this status, visit the Fortinet Support website.
When contacting customer support, you must provide the FortiToken serial number as well as the FortiGate or FortiAuthenticator serial number to which the token is assigned.