FortiToken
FortiToken is a multi-factor authentication (MFA) solution by Fortinet that
enhances security by requiring users to provide multiple forms of
verification before accessing systems. It offers both hardware tokens and
the FortiToken Mobile application, which generates one-time passwords
(OTPs) for secure authentication.
Configuration Steps:
1. Install FortiToken Mobile:
o Download and install the FortiToken Mobile app on your
smartphone from the Apple App Store or Google Play Store.
2. Assign a Token to a User:
o Log in to your FortiGate or FortiAuthenticator management
interface.
o Navigate to the user management section and assign a
FortiToken to the desired user.
o The user will receive an activation code via email or SMS.
3. Activate the Token:
o Open the FortiToken Mobile app on your smartphone.
o Use the app to scan the QR code provided in the activation
email or enter the activation code manually.
o The token will be added to the app, displaying a six-digit OTP
that refreshes periodically.
4. Configure Two-Factor Authentication (2FA) on FortiGate:
o In the FortiGate interface, go to the VPN or login settings
where you want to enforce 2FA.
o Select the user group that requires 2FA and ensure that the
FortiToken is associated with these users.
o Apply the settings to enforce MFA for the selected users.
5. FortiToken 410
o FIDO Security Key for Passwordless Online Login Digital
transformation, rapid cloud adoption, and the global shift to
remote work have accelerated the evolution of authentication
methods. FortiToken 410 is our all-in-one USB security key that
can be used for multi-factor authentication (MFA) or
passwordless login when using online services. FortiToken 410
supports FIDO U2F and FIDO2 protocols. It reduces reliance on
passwords while increasing security and protecting user
privacy.
o For more Info:
https://www.fortinet.com/content/dam/fortinet/assets/data-
sheets/fortitoken-400.pdf
6. FortiToken 310
o Versatile Secure Digital Certificate Storage and
Usage:
FortiToken 310 is a Smart Card USB token that is a
USB-interfaced device offering a variety of security
capabilities including certificate-based public key
infrastructure (PKI) authentication, digital signing,
encrypting/decrypting files such as emails and
documents, VPN client authentication, and more.
o https://www.fortinet.com/content/dam/fortinet/assets/data-
sheets/FortiToken_300.pdf
7. FortiToken 210
o The Fortinet FortiToken 210 is a hardware token
designed to provide secure and reliable access to
computer systems. This device is engineered to meet
the demands of modern security environments,
offering features such as OTP generation every 30 or
60 seconds and a 6-digit high contrast LCD for easy
readability. Compliance with standards such as FCC,
FIPS 140-2, and RoHS, along with a durable, tamper-
resistant, and water-resistant design, ensures that the
FortiToken 210 is a dependable choice for enhancing
your security posture. With the inclusion of a built-in
lithium battery boasting up to 3 years of lifetime, users
can enjoy long-term, maintenance-free operation.
Whether for personal use or within an enterprise
setting, the Fortinet FortiToken 210 offers a
comprehensive solution for anyone looking to bolster
their computer security.
o https://www.fortinet.com/content/dam/fortinet/assets/
data-sheets/fortitoken.pdf
8. FortiToken ORDERING GUIDE:
o https://www.fortinet.com/content/dam/fortinet/assets/data-
sheets/og-fortitoken.pdf
9. FortiToken PRICE LIST 2024:
o https://itprice.com/fortinet-price-list/forti%20token.html
How It Works:
Once configured, when a user attempts to access a protected resource
(e.g., VPN or web portal), they will be prompted to enter their regular
password followed by the OTP generated by the FortiToken Mobile app.
This two-step verification process ensures that even if a user's password is
compromised, unauthorized access is prevented without the OTP.
For a visual demonstration and more detailed instructions, you can refer
to the following video: https://youtu.be/mmX96YbegNU