Introduction
FortiTokens are security tokens used as part of a multi-factor authentication (MFA) system on FortiGate/FortiOS and FortiAuthenticator devices.
The token produces a temporary six or eight digit (configurable) code that is used to prove one's identity electronically as a prerequisite for accessing network resources.
There are many types of hardware and software based tokens, sometimes referred to as dongles, key fobs, authentication tokens, USB tokens, and cryptographic tokens.
FortiToken is available as either a physical or a mobile token, as described below.
Physical token
-
FortiToken 210: These physical tokens display their code on the device itself, and provide two-factor authentication for RADIUS, LDAP, and 802.1X wireless authentication, as well as Fortinet single sign-on (FSSO).
This kind of two-factor authentication improves security by moving away from use of static passwords.
To transfer FortiToken tokens from one FortiGate or FortiAuthenticator device to another, visit the Fortinet Support website.
When contacting customer support, you must provide the FortiToken serial number as well as the FortiGate or FortiAuthenticator serial number to which the token is assigned.
You can also request a seed file in various formats for import into FortiGate or FortiAuthenticator or a third part OATH compliant MFA server.
Mobile token
-
FortiToken Mobile: These tokens produce their codes in an application you can download to your Android, iOS, or Windows device that is used just like a FortiToken-210 but without the need for a physical token.
FortiToken Mobile uses push technology to send login attempt notifications to a user's smartphone or tablet where they can verify the login with a single tap (iOS and Android versions only).
Users can download their free FortiToken Mobile application from the App Store (iOS), Google Play (Android), or the Microsoft Store (Windows).