Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Daniel__
New Contributor II

FTMv4 push notifications nowhere to be seen

I cannot for the world get the push notifications to work, it is if the Authenticator is not trying to send any out.

 

- FortiAuthenticator interface available from the Mobile device, check (not seeing any requests come this way though)

- Radius client "Enable FortiToken Mobile push notifications authentication", check

- "Regular" 2FA works fine with challenge/response

- Re-installed FortiToken Mobile App, Organisational push (Name and Logo) works fine.

- FortiToken mobile flashed that it had downloaded (didn't see it all) something that seemed to indicate push enabled setup.

 

I am not seeing any packets go out from the FortiAuthenticator that would indicate it is trying to send any notifications.

 

4 REPLIES 4
Alienated
New Contributor

Did you ever get this resolved? I have gone through the exact same steps (even got the message about push notifications). I am using an Android phone and haven't tested other devices yet.

Daniel__
New Contributor II

I actually eventually got it sorted, I am using Fortigates as the auth client and this needed to be of a certain level of firmware, for it to work out of the box you need to be on 5.6.3 and the forticlient needs to be using I believe 5.6.x as well, and the fac needs to have the setting to allow push.

 

if you only have version 5.6.2 on the fortigate for example, you will not get the "push" button in the forticlient but can use "push" as the second factor passcode and the fac will try and push a notification.

 

So be advice I have is to update everything to the latest and try again.

 

Oh and if you want to add password reset to the forticlient in an AD structure you need to set a cli option to be "enable password reset" (or similar, cant remember on top of my head.)

 

RobertReynolds

Im really struggling to get this working too...

 

[ul]
  • FG-60D (192.168.2.1) on 5.6.3 is a RADIUS Client of FAC 5.2.0 (192.168.2.163) .
  • RADIUS Client setting in FAC has ForitiToken mobile ticked
  • VIP external mappings and policies through Fortigate to FAC for port 443, 2195. 2196, 5223
  • Trusted Certificate for FAC fqdn, and fqdn defined for fac ftm access
  • I have 3 other remote Fortigates, again set up as remote RADIUS clients.
  • When I untick FTM in the Radius Client settings on FAC, everything works as expected by entering the 6 digit code.
  • When I test FTM Push directly from the FGT using a FTM issued by FG, I get the push notification on my phone.[/ul]

     Ive also run the following on the 60D, not sure if its required:

     

    config system ftm-push

        set server-port 4433

        set server-ip 192.168.2.163

        set status enable

    end

     

    Ive attacehed debug from FAC, it wont let me attach 2 files but this is all i see using diag sniffer, looks like only RADIUS and FSSO packets:

     

    191.545026 internal in 192.168.2.163.8000 -> 192.168.2.1.1031: psh 323692930 ack 3089809365 
    191.545168 internal out 192.168.2.1.1031 -> 192.168.2.163.8000: ack 323692946
    201.584775 internal in 192.168.2.163.8000 -> 192.168.2.1.1031: psh 323692946 ack 3089809365
    201.584994 internal out 192.168.2.1.1031 -> 192.168.2.163.8000: ack 323692962
    204.726050 internal out 192.168.2.1.1046 -> 192.168.2.163.1812: udp 117
    204.852531 internal in 192.168.2.163.1812 -> 192.168.2.1.1046: udp 113
    204.886565 internal out 192.168.2.1.1046 -> 192.168.2.163.1812: udp 120
    211.624507 internal in 192.168.2.163.8000 -> 192.168.2.1.1031: psh 323692962 ack 3089809365
    211.624727 internal out 192.168.2.1.1031 -> 192.168.2.163.8000: ack 323692978
    220.217738 internal out 192.168.2.1.1031 -> 192.168.2.163.8000: psh 3089809365 ack 323692978

     

    Have I missed something simple? Thanks :)

  • xsilver_FTNT

    Hi RobertReynolds,

     

    some time ago I tried to bring this KB article up to clarify whole PUSH notifications setup.
    https://community.fortinet.com/t5/FortiAuthenticator/Technical-Tip-FortiToken-Push-on-FortiAuthentic...


    It sounds like you did almost everything, but do you have push receiver enabled on interface of FortiAuthenticator ?

    I'm referring to KB and section "3) Enable push notification on the interface"

    Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
    AAA, MFA, VoIP and other Fortinet stuff

    Labels
    Top Kudoed Authors