FortiGate · FortiOS 7.4

FortiGate and FAC commands for IKEv2 MFA troubleshooting

Quick answer #

Capture one login across FortiGate and FortiAuthenticator, then compare event timestamps. A phone displaying an approved push does not establish that FortiGate received and accepted the final authentication result before its waiting period expired.

Scope: FortiGate FortiOS 7.4.1 and later within the 7.4 branch; current IKE debug syntax; FAC-backed RADIUS/EAP IKEv2. FAC UI paths depend on release. Runtime debugging, not a firmware-specific fix.

Prepare the evidence #

Record the FortiOS, FortiClient and FAC versions, VPN name, username, client public IP and test time. Check that the clocks agree closely enough to correlate logs. With the user's cooperation, compare manual OTP with push once. A successful OTP narrows the investigation, but does not prove that every push-specific dependency is healthy.

Stop and clean up #

Stop and clean up
FortiOS 7.4 · Traffic VDOM; administrative scope as described below

Diagnostic state
diagnose debug disable
Diagnostic state
diagnose debug reset
Diagnostic state
diagnose vpn ike log filter clear

Collect one FortiGate attempt #

Coordinate with other administrators before resetting debug state. In the VPN's VDOM, replace the address with the client's public source as seen by FortiGate:

Collect one FortiGate attempt
FortiOS 7.4 · Traffic VDOM; administrative scope as described below

Diagnostic state
diagnose debug disable
Diagnostic state
diagnose debug reset
Diagnostic state
diagnose debug console timestamp enable
Diagnostic state
diagnose vpn ike log filter clear
Diagnostic state

Replace these example values: 198.51.100.10.

diagnose vpn ike log filter rem-addr4 198.51.100.10
Diagnostic state
diagnose debug application ike -1

Stop promptly with the cleanup block on this page; shared debug state affects other administrators.

Output may contain sensitive operational data.
Diagnostic state
diagnose debug application fnbamd -1

Stop promptly with the cleanup block on this page; shared debug state affects other administrators.

Output may contain sensitive operational data.
Diagnostic state
diagnose debug enable

Stop promptly with the cleanup block on this page; shared debug state affects other administrators.

Reproduce one attempt and stop promptly. The IKE address filter does not limit fnbamd to that user, so authentication output can include other users and sensitive details; IKE debugging may also expose key material. Keep raw captures in restricted storage and redact them before sharing. Do not leave this running through a busy authentication period.

Read the same attempt on FAC #

Use the FAC RADIUS diagnostic view available under https://<FAC-IP>/debug/ and select the RADIUS debug facility for that release. Correlate the username and request/session identifiers as well as the timestamp. Distinguish push initiation, FAC receipt of approval and the final reply sent to FortiGate; these are separate milestones.

Locate the failure boundary #

If FAC never records approval, investigate the push return path and FAC processing. If FAC sends Access-Accept after FortiGate reports FNBAM_TIMEOUT, timing is the immediate failure. If FAC accepts promptly but FortiGate rejects the reply, examine validation and session matching. If authentication succeeds on FortiGate, continue with EAP/IKE completion and the client log.

Review timers after collecting evidence #

Compare global remoteauthtimeout, the FAC RADIUS object's timeout, and the tunnel's negotiate-timeout. They are separate settings. Read their effective values from the configuration, including defaults, before proposing a change. Avoid disabling response validation or declaring a particular firmware regression from the token screen alone. An escalation should include one correlated attempt and the precise stage that failed.

Sources

Documentation reviewed: 8 October 2026