FortiToken
Second factor for VPN, admin access and applications
- Licensing
- Per token (hardware) or per user (mobile / cloud)
- Form factors
- Hardware OTP token, FortiToken Mobile, FortiToken Cloud
- Integrations
- FortiGate, FortiAuthenticator, FortiClient, third-party RADIUS
FortiToken supplies the second authentication factor for FortiGate administrative access, VPN and SSL VPN logins, and applications behind FortiAuthenticator, as hardware tokens, a mobile app, or a cloud service with no infrastructure to run.
Where it fits, and where it stops fitting
Check the FortiGate's built-in FortiToken ceiling before planning a rollout: it is 500 on entry-level models and 20,000 at the high end, and a growing organisation genuinely reaches 500. Hardware tokens still matter where phones are not permitted or not carried, manufacturing floors, secure facilities, clinical settings.
Highlights
- Hardware, mobile and cloud form factors
- Protects firewall admin access, the highest-value credential you own
- Works with FortiAuthenticator for application MFA
- No infrastructure to run in the cloud tier
Typical deployments
- MFA on FortiGate administrative logins
- Second factor for remote-access VPN
- Environments where personal phones are not permitted
What to work out first
FortiToken provides the second factor for FortiGate administrative access, VPN and SSL VPN logins, and applications behind FortiAuthenticator, as hardware tokens, as a mobile app, or as a cloud service with no infrastructure to run.
Hardware tokens still matter for environments where phones are not permitted or not carried, manufacturing floors, secure facilities, clinical settings. Most organisations end up with a mix.
Every FortiGate has a built-in FortiToken ceiling, from 500 on the entry-level models to 20,000 at the high end, so the firewall itself can cap your MFA rollout.
Questions worth answering before you order
Hardware, mobile or cloud?
Mobile is cheapest and most convenient. Hardware for people who cannot carry a phone at work. Cloud where you would rather not run the seed management yourself.
How many users, and does the firewall support that many?
Check the FortiGate's max-FortiTokens figure. On an entry-level model it is 500, which a growing organisation can genuinely reach.
What are you protecting?
Administrative access to the firewall itself should have MFA on day one; it is the highest-value credential in the estate and the cheapest thing on this page to protect.
What this includes
Fortinet publishes no throughput table for this product; it is licensed per user, endpoint, workload or account. What follows is capability and sizing, not benchmarks.
What you are buying
| Licensing | Per token (hardware) or per user (mobile / cloud) |
|---|---|
| Form factors | Hardware OTP token, FortiToken Mobile, FortiToken Cloud |
| Integrations | FortiGate, FortiAuthenticator, FortiClient, third-party RADIUS |
How this is sized
Fortinet licenses this product per user, endpoint, workload or account rather than by appliance throughput, so there is no comparable performance table to publish. We size it from your actual environment, tell us the numbers and we will work it through with you.
| Licensing | Per token (hardware) or per user (mobile / cloud) |
|---|
Sources
- Fortinet product line overview, retrieved 2026-09-01
Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order; we will.