0% found this document useful (0 votes)
181 views4 pages

Fortitoken One-Time Password Token

fortitoken
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
181 views4 pages

Fortitoken One-Time Password Token

fortitoken
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
You are on page 1/ 4

DATA SHEET

FortiToken One-Time Password Token


TM

Mobile (FTM) One-Time Password (OTP) Application with Push Notification


Hardware Token Time-Based OTP Form-Factors: FTK-200, FTK-200CD and FTK-220

Overview
Fortinet’s FortiToken Mobile (FTM) and hardware OTP Tokens (FTK-
200, FTK-200CD and FTK-220) are fully integrated with FortiClient,
protected by FortiGuard and leverage direct management and use
within the FortiGate and FortiAuthenticator security platforms. Secure
your network with Fortinet’s easy-to-manage, easy-to-use Two-
Factor Authentication solutions.

PRODUCT OFFERINGS
FortiToken Mobile
FortiToken Mobile is an OATH compliant OTP generator application
for the mobile device supporting both time-based (TOTP) and event-
based (HOTP) tokens.

FortiToken 200/200CD
FortiToken 200 is part of Fortinet’s broad and flexible two-factor
authentication offering. It is an OATH compliant, TOTP. It is a small,
keychain-sized device that offers real mobility and flexibility for the
end-user.

There is no client software to install; simply press the button and the
FortiToken 200 generates and displays a secure one-time password
every 60 seconds to verify user identity for access to critical networks
and applications. The big LCD screen of the rugged FortiToken 200 is
much easier to read than other OTP tokens and there is an indicator
on the screen displaying the time left until the next OTP generation.
FortiToken 200CD tokens are shipped with an encrypted activation CD
for the ultimate in OTP token seed security.

FortiToken 220
The FortiToken 220 OTP token is a mini credit card form factor token.
The card is shipped with a precut hole for key ring application. Its
sleek and slim design fits neatly into your wallet.
DATA SHEET | FortiTokenTM One-Time Password Token

HIGHLIGHTS
Strong Authentication at your Fingertips Leverage Existing Fortinet Platforms
It is the client component of Fortinet’s highly secure, simple Besides offering out-of-the-box interoperability with any
to use and administer, and extremely cost effective two- time-based OATH compliant authentication server, such
factor solution for meeting your strong authentication needs. as the FortiAuthenticator™ from Fortinet, the FortiToken
This application makes your Android, iOS and Windows can also be used directly with the FortiGate® consolidated
mobile devices behave like a hardware-based OTP token security platform, including High Availability configurations.
without the hassles of having to carry yet another device. FortiGate has an integrated authentication server for
Push notification allows you to view login details on your validating the OTP as the second authentication factor for
mobile device to approve or deny with one tap. SSL VPN, IPsecVPN, Captive Portal and Administrative
Alternatively, you can deploy hardware-based OTP token to login, thereby eliminating the need for the external RADIUS
prevent users’ passwords from stolen, phishing, dictionary server ordinarily required when implementing two-factor
and brute-force attacks. solutions.

Ultra-Secure Token Provisioning Online Activation with FortiGuard®


What makes FortiToken mobile OTP application superior to You can activate your FortiToken tokens online directly
others on the market is that while being simple to use for from FortiGate or FortiAuthenticator using the FortiGuard®
the end user, and easy to administer and provision for the Center, which maintains your token seeds in a managed
system administrator, it is actually more secure than the service repository. Once the seeds are activated, they can
conventional hard token. The token seeds are generated no longer be accessed from FortiGuard,ensuring that your
dynamically, minimizing online exposure. Binding the seeds are safe from compromise. Alternatively, Fortinet also
token to the device is enforced and the seeds are always offers an encrypted activation CD solution.
encrypted at rest and in motion.

Privacy and Control


FortiToken Mobile cannot change settings on your phone, • “Send Feedback by Email”, to automatically
take pictures or video, record or transmit audio, nor can populate the “Sender” field
it read or sendemails. Further, it cannot see your browser • nternally share files between applications to prepare
history, and it requires your permission to send you an attachment to be sent by email for “Send
notifications or to change any settings. Feedback by Email”
And, FortiToken Mobile cannot remotely wipe your phone. • FortiToken must keep the phone awake while it
Any visibility FortiToken Mobile requires is to verify your is upgrading the internal database to avoid data
OS version to determine app version compatibility. While corruption
FortiToken Mobile cannot change any settings without
your permission, the following permissions are relevant to
FortiToken Mobile operations:
• Access to camera for scanning QR codes for easy
token activation
• TouchID/FaceID: used for app security, respectively
• Access to the Internet for communication to
activate tokens and receive push notifications

2
DATA SHEET | FortiTokenTM One-Time Password Token

ADVANTAGES
• Unique token provisioning service via FortiGuard™
minimizes provisioning overhead and ensures
maximum seed security
• Perpetual token license and unlimited device
transfers eliminate annual subscription fees
• Scalable solution leveraging existing end-user
devices offers low entry cost and TCO
• Reduces costs and complexity by using your
existing FortiGate as the two-factor authentication
server
• Zero footprint solution

MAIN FEATURES

FortiToken Mobile FortiToken Hardware Devices


• OATH time- and event-based OTP generator • Integrated with FortiClient™ and protected by
• Login details pushed to phone for one-tap approval FortiGuard

• Patented Cross Platform Token Transfer • OATH TOTP compliant

• PIN/Fingerprint protected application • Large, easy-to-read, LCD display

• Copy OTP to the clipboard • Long-life Lithium battery

• OTP time interval display • Tamper-resistant/tamper-evident packaging

• Serial Number display


• Token and app management
• Self-erase brute-force protection
• Apple watch compatibility

SUPPORTED PLATFORMS

FortiToken Mobile FortiToken Hardware Devices


• OATH time- and event-based OTP generator • FortiOS 4.3 and up
• Login details pushed to phone for one-tap approval • FortiAuthenticator — all versions
• iOS (iPhone, iPod Touch, iPad), Android, Windows
Phone 8, 8.1, Windows 10 and Windows Universal
Platform
• WiFi-only devices supported (for over-the-air token
activation)

3
DATA SHEET | FortiTokenTM One-Time Password Token

Specifications
FORTITOKEN 200/200CD FORTITOKEN 220 FORTITOKEN MOBILE
Onboard Security Algorithm OATH-TOTP (RFC6238) OATH-TOTP (RFC6238) Onboard Security Algorithm OATH time and event based
OTP Spec 60 seconds, SHA-1 60 seconds, SHA-1 OTP generator
Component 6-digit high contrast LCD display Built-in button, 6-character LCD screen, OTP Spec RFC 6238, RFC 4226
Globally unique serial number Supported Platforms iOS (iPhone, iPod Touch, iPad,
Dimensions (Length x Width x Height) 61.5 x 27.5 x 11.5mm 68 x 38 x 1 mm iWatch), Android, Windows
Phone 8/8.1, Windows 10 and
Hardware Certification RoHS Compliant RoHS, CE, FCC (certificates pending)
Windows Universal Platform
Operating Temperature 14–122°F (-10–50°C 32–122°F (0–50°C)
Over-the-Air Token Activation WiFi-only devices supported
Storage Temperature -4–158°F (-20–70°C) 14–140°F (-10–60°C)
One-Tap Approval Login details pushed to phone
Water-Resistant IP54 (Ingress Protection) IP54 (Ingress Protection)
PIN/Fingerprint/Facial Security
Casing Hard Molded Plastic (ABS) Tamper-Evident Hard Molded Plastic (ABS) Tamper-Evident
Serial Number Display
Secure Storage Medium Static RAM Static RAM
Token and App Management
Battery Type Standard Lithium Battery Standard Lithium Battery
Self-Erase Brute-Force Protection
Battery Lifetime 3–5 Years 3–5 Years
Customization Available* Casing Color, Company Logo, Faceplate Casing Color, Company Logo, Faceplate
Branding Branding
* Customizations are quantity-based

PLATFORM SCALABILITY
FortiToken scalability for specific platforms can be found in the Fortinet Product Matrix located at http://www.fortinet.com/sites/default/files/productdatasheets/Fortinet_Product_Matrix.pdf

Order Information
Product SKU Description
FortiToken Software License Key FTM-ELIC-5 Software one-time password tokens for iOS, Android and Windows Phone mobile devices. Perpetual licenses for 5 users. Electronic licence certificate.
FTM-ELIC-10 Software one-time password tokens for iOS, Android and Windows Phone mobile devices. Perpetual licenses for 10 users. Electronic licence certificate.
FTM-ELIC-20 Software one-time password tokens for iOS, Android and Windows Phone mobile devices. Perpetual licenses for 20 users. Electronic licence certificate.
FTM-ELIC-50 Software one-time password tokens for iOS, Android and Windows Phone mobile devices. Perpetual licenses for 50 users. Electronic licence certificate.
FTM-ELIC-100 Software one-time password tokens for iOS, Android and Windows Phone mobile devices. Perpetual licenses for 100 users. Electronic licence certificate.
FTM-ELIC-200 Software one-time password tokens for iOS, Android and Windows Phone mobile devices. Perpetual licenses for 200 users. Electronic licence certificate.
FTM-ELIC-500 Software one-time password tokens for iOS, Android and Windows Phone mobile devices. Perpetual licenses for 500 users. Electronic licence certificate.
FTM-ELIC-1000 Software one-time password tokens for iOS, Android and Windows Phone mobile devices. Perpetual licenses for 1000 users. Electronic licence certificate.
FTM-ELIC-2000 Software one-time password tokens for iOS, Android and Windows Phone mobile devices. Perpetual licenses for 2000 users. Electronic licence certificate.
FTM-ELIC-5000 Software one-time password tokens for iOS, Android and Windows Phone mobile devices. Perpetual licenses for 5000 users. Electronic licence certificate.
FTM-ELIC-10000 Software one-time password tokens for iOS, Android and Windows Phone mobile devices. Perpetual licenses for 10000 users. Electronic licence certificate.
FortiToken 200 FTK-200-5 5 pieces, one-time passwork token, time-based password generator. Perpetual license.
FTK-200-10 10 pieces, one-time passwork token, time-based password generator. Perpetual license.
FTK-200-20 20 pieces, one-time passwork token, time-based password generator. Perpetual license.
FTK-200-50 50 pieces, one-time passwork token, time-based password generator. Perpetual license.
FTK-200-100 100 pieces, one-time passwork token, time-based password generator. Perpetual license.
FTK-200-200 200 pieces, one-time passwork token, time-based password generator. Perpetual license.
FTK-200-500 500 pieces, one-time passwork token, time-based password generator. Perpetual license.
FTK-200-1000 1000 pieces, one-time passwork token, time-based password generator. Perpetual license.
FTK-200-2000 2000 pieces, one-time passwork token, time-based password generator. Perpetual license.
FortiToken 200CD FTK-200CD-10 FortiToken OTP hardware generator shipped with CD containing encrypted seed file — 10-pack.
FTK-200CD-20 20 pieces one-time password token, time-based password generator shipped with encrypted seed file on CD. Perpetual license.
FTK-200CD-50 FortiToken OTP hardware generator shipped with CD containing encrypted seed file — 50-pack.
FTK-200CD-100 FortiToken OTP hardware generator shipped with CD containing encrypted seed file — 100-pack.
FortiToken 220 FTK-220-5 5 pieces, one-time password token, time-based password generator. Perpetual license.
FTK-220-10 10 pieces, one-time password token, time-based password generator. Perpetual license.
FTK-220-20 20 pieces, one-time password token, time-based password generator. Perpetual license.
FTK-220-50 50 pieces, one-time password token, time-based password generator. Perpetual license.
FTK-220-100 100 pieces, one-time password token, time-based password generator. Perpetual license.

www.fortinet.com

Copyright © 2020 Fortinet, Inc. All rights reserved. Fortinet®, FortiGate®, FortiCare® and FortiGuard®, and certain other marks are registered trademarks of Fortinet, Inc., and other Fortinet names herein may also be registered and/or common law
trademarks of Fortinet. All other product or company names may be trademarks of their respective owners. Performance and other metrics contained herein were attained in internal lab tests under ideal conditions, and actual performance and other results
may vary. Network variables, different network environments and other conditions may affect performance results. Nothing herein represents any binding commitment by Fortinet, and Fortinet disclaims all warranties, whether express or implied, except to
the extent Fortinet enters a binding written contract, signed by Fortinet’s General Counsel, with a purchaser that expressly warrants that the identified product will perform according to certain expressly-identified performance metrics and, in such event,
only the specific performance metrics expressly identified in such binding written contract shall be binding on Fortinet. For absolute clarity, any such warranty will be limited to performance in the same ideal conditions as in Fortinet’s internal lab tests.
Fortinet disclaims in full any covenants, representations, and guarantees pursuant hereto, whether express or implied. Fortinet reserves the right to change, modify, transfer, or otherwise revise this publication without notice, and the most current version
of the publication shall be applicable. Fortinet disclaims in full any covenants, representations, and guarantees pursuant hereto, whether express or implied. Fortinet reserves the right to change, modify, transfer, or otherwise revise this publication without
notice, and the most current version of the publication shall be applicable.
FST-PROD-DS-FT2HR4 FTK-OTP-DAT-R14-202006

You might also like