Frequently Asked Questions
Why does IKEv2 with FortiToken fail intermittently on FortiOS 7.2.x?
FortiGate supports both FortiToken Push and manual token-code authentication for IKEv2. However, FortiOS 7.2.x does not always reliably distinguish between these two authentication flows.
As a result, the FortiGate may initiate a push or separate token request even though the password and OTP have already been submitted together. Typical symptoms include inconsistent authentication errors, a timeout after the password has been accepted, or a connection that only succeeds intermittently.
This behavior was corrected starting with FortiOS 7.4.8. In our tests with FortiOS 7.4.11, authentication using password+OTP works reliably even when FortiToken Push is enabled.
Enable “Combined Credentials” in VPN Tracker and enter a current FortiToken code when connecting. VPN Tracker automatically combines it with the stored password. For more information, see Fortinet VPN 2FA Not Working.
We recommend updating the FortiGate to FortiOS 7.4.8 or later. If an SSL VPN connection is currently used as a fallback, schedule the update during a maintenance window and retain the existing connection until the IKEv2 setup has been tested successfully.
As a result, the FortiGate may initiate a push or separate token request even though the password and OTP have already been submitted together. Typical symptoms include inconsistent authentication errors, a timeout after the password has been accepted, or a connection that only succeeds intermittently.
This behavior was corrected starting with FortiOS 7.4.8. In our tests with FortiOS 7.4.11, authentication using password+OTP works reliably even when FortiToken Push is enabled.
Enable “Combined Credentials” in VPN Tracker and enter a current FortiToken code when connecting. VPN Tracker automatically combines it with the stored password. For more information, see Fortinet VPN 2FA Not Working.
We recommend updating the FortiGate to FortiOS 7.4.8 or later. If an SSL VPN connection is currently used as a fallback, schedule the update during a maintenance window and retain the existing connection until the IKEv2 setup has been tested successfully.