- General Information
- Fortinet, Inc
- Manufacturer Website Address
- Brand Name
- Product Line
- Packaged Quantity
- Product Type
- Security Token
Enable two-factor authentication with FortiToken Mobile (FTM) One-Time Password (OTP) Application with Push Notifications or a Hardware Time-Based OTP Token
Fortinet FortiToken Mobile (FTM) and hardware OTP Tokens are fully integrated with FortiClient, protected by FortiGuard, and leverage direct management and use within the FortiGate and FortiAuthenticator security platforms. Fortinet two-factor authentication solutions are easy to manage and easy to use.
HIGHLIGHTS | Convenient, Strong Authentication
FortiToken is the client component of Fortinet's highly secure, simple to use and administer, and cost-effective two-factor solution for meeting strong authentication needs. This application makes Android, iOS, and Windows mobile devices behave like a hardware-based OTP token without the hassle of having to carry yet another device. Push notification shows details on the mobile device to approve or deny with one tap. Alternatively, hardware-based OTP tokens can be used to prevent users' passwords from being stolen via phishing, dictionary, and brute-force attacks.
Ultra-Secure Token Provisioning
FortiToken Mobile is simple to use and administer and provision for the system administrator. The token seeds are generated dynamically, minimizing online exposure. Binding the token to the device is enforced and the seeds are always encrypted at rest and in motion.
Privacy and Control
FortiToken Mobile cannot change settings on a phone, take pictures or video, record or transmit audio, or read or send emails. Further, it cannot see browser history, and it requires permission to send notifications or to change any settings. Additionally, FortiToken Mobile cannot remotely wipe a phone. Any visibility FortiToken Mobile requires is to verify the OS version to determine app version compatibility. While FortiToken Mobile cannot change any settings without permission, the following permissions are relevant to FortiToken Mobile operations:
- Access to camera for scanning QR codes for easy token activation
- TouchID/FaceID used for app security
- Access to the internet for communication to activate tokens and receive push notifications
- "Send Feedback by Email", to automatically populate the "Sender" field
- Internally share files between applications to prepare an attachment to be sent by email for "Send Feedback by Email"
- FortiToken must keep the phone awake while it is upgrading the internal database to avoid data corruption
Highlights continued | Leverages Existing Fortinet Platforms
Besides offering out-of-the-box interoperability with any time-based OATH compliant authentication server such as FortiAuthenticator, FortiToken can also be used directly with FortiGate Next-Generation Firewalls, including with high availability configurations.
FortiGate has an integrated authentication server for validating the OTP as the second authentication factor for SSL VPN, IPsec VPN, captive portal, and administrative login. This eliminates the need for the external RADIUS server that is typically required when implementing two-factor solutions.