FortiToken Cost Breakdown: What Fortinet MFA Really Costs vs Third-Party Solutions
Adding MFA to FortiGate should be straightforward. FortiGate is already on your network. Fortinet has its own MFA products — FortiToken Mobile and FortiToken 200 hardware — that integrate natively. No third-party tools, no RADIUS proxy, no extra infrastructure.
That’s the pitch. The reality, for many organizations, is that native FortiToken licensing scales less predictably than expected — and FortiAuthenticator, Fortinet’s centralized token management appliance, adds a separate infrastructure cost that isn’t always visible at the point of the initial FortiGate purchase.
This article breaks down what Fortinet MFA actually costs, how the licensing model works, and what the numbers look like for a 100-user organization choosing between native FortiToken and a third-party RADIUS MFA approach.
What the Fortinet Native MFA Stack Looks Like
Fortinet’s MFA ecosystem has three components that typically come up in a FortiGate MFA conversation:
FortiToken Mobile is a software OTP application for iOS, Android, and Windows devices. It’s OATH-compliant and time-based (TOTP). The key operational detail: FortiToken Mobile licenses are sold as perpetual licenses registered to a specific FortiGate appliance (for licenses issued after August 2025). A license for 100 users is tied to that one FortiGate — not to your organization or your user directory.
FortiToken 200 / 200CD is Fortinet’s hardware OTP token — a small keychain device that generates a 6-digit code every 60 seconds. The 200CD variant ships with an encrypted activation CD for seed security. These are also perpetual, per-unit licenses, tied to the appliance they’re activated on. Note: the FortiToken 200B has been discontinued; current hardware token offerings are the FortiToken 210, 310, and 410 series.
FortiAuthenticator is a dedicated appliance (physical or virtual) that centralizes FortiToken management across multiple FortiGate units. Without FortiAuthenticator, each FortiGate handles its own token pool independently — licenses registered to FortiGate-A cannot be used by FortiGate-B.
FortiToken Mobile Pricing: What 100 Users Actually Costs
FortiToken Mobile licenses are available in fixed user-count bundles. Based on publicly available pricing from authorized resellers (list price, USD):
| Bundle | Users covered | List price | Per-user cost |
|---|---|---|---|
| FTM-ELIC-10 | 10 | $958 | ~$96/user |
| FTM-ELIC-25 | 25 | $2,246 | ~$90/user |
| FTM-ELIC-50 | 50 | $4,178 | ~$84/user |
| FTM-ELIC-100 | 100 | $7,638 | ~$76/user |
| FTM-ELIC-200 | 200 | $13,787 | ~$69/user |
Source: AVFirewalls.com (authorized Fortinet reseller), list prices as of 2025. Actual prices vary by reseller and region.
For 100 users on a single FortiGate, the list price is $7,638 — a one-time perpetual license. That number looks reasonable until you factor in what it doesn’t include.
What it doesn’t include:
- The license is tied to one specific FortiGate appliance. If you need to manage FortiTokens across multiple FortiGate appliances — for example, at different locations — you either need separate license bundles for each FortiGate or FortiAuthenticator to centralize the token pool.
- For licenses issued after August 2025, the license also cannot be transferred to a different FortiGate appliance (except in RMA scenarios), so replacing the appliance may require purchasing a new license or migrating to FortiIdentity Cloud.
- If you need hardware tokens for users without smartphones, that’s a separate purchase — FortiToken 210/310/410 hardware, also perpetual per-unit, priced separately.
The FortiAuthenticator Factor
For organizations with more than one FortiGate unit, FortiAuthenticator is the standard solution to the per-appliance license problem. It centralizes FortiToken management across multiple firewalls and supports a broader range of authentication methods.
FortiAuthenticator is available as either a physical appliance or a virtual appliance (FAC-VM). The base VM license supports 100 users. Pricing for the virtual appliance adds to the overall MFA infrastructure cost.
The practical implication: organizations managing multiple FortiGate appliances either need separate FortiToken license bundles for each appliance or FortiAuthenticator to centralize the token pool. The “simple native integration” path becomes more complex as the infrastructure grows.
What a Third-Party RADIUS MFA Approach Looks Like
A RADIUS proxy approach adds an MFA layer between FortiGate and Active Directory without FortiToken licensing or FortiAuthenticator. FortiGate sends RADIUS authentication requests to the proxy, which validates the password against AD/LDAP and enforces a second factor before returning an Access-Accept.
The cost structure is different:
- Subscription per-user (rather than perpetual per-appliance).
- One server covers multiple FortiGate units, plus other network devices (Cisco, Palo Alto, etc.) from the same deployment.
- Hardware tokens: any OATH TOTP/HOTP-compatible device, not limited to Fortinet’s token line.
- No FortiAuthenticator or any separate appliance is required to centralize token management across multiple FortiGate devices.
The trade-off: a RADIUS proxy requires a separate server (or cloud service subscription), whereas FortiToken Mobile works directly with FortiGate’s built-in authentication server for single-appliance deployments.
TCO Comparison: 100 Users, 3-Year Horizon
The table below compares the cost structure for a 100-user organization over three years. Note: third-party subscription pricing varies by vendor and tier — the comparison is structural, not a specific dollar figure for Protectimus, since pricing depends on deployment type and negotiated rates.
| Cost factor | FortiToken Mobile (single FortiGate) | FortiToken Mobile + FortiAuthenticator (multi-appliance) | Third-party RADIUS MFA |
|---|---|---|---|
| Initial license cost (100 users) | ~$7,638 (list) | ~$7,638 + FAC VM license | Subscription (year 1) |
| Year 2–3 cost | $0 (perpetual) | $0 (perpetual) | Subscription (years 2–3) |
| Second FortiGate unit | Second license bundle required | Covered by FortiAuthenticator | Covered — one server |
| Hardware tokens | FortiToken 210/310/410 (additional cost) | FortiToken 210/310/410 (additional cost) | Any OATH token |
| Covers Cisco/Palo Alto/NPS | No | No | Yes |
| License portability | License cannot be transferred to another FortiGate appliance (post Aug 2025) | License cannot be transferred to another FortiGate appliance (post Aug 2025) | Per active user subscription |
The break-even point shifts depending on two variables:
- Number of FortiGate units. A single-appliance deployment where user turnover is low and no hardware tokens are needed is the strongest case for FortiToken Mobile — the perpetual license amortizes well over time.
- Scope of the MFA deployment. An organization that also needs MFA for Cisco ASA VPN, Palo Alto GlobalProtect, or SonicWall gets no value from FortiToken Mobile for those services. A RADIUS proxy covers all of them from the same deployment and the same user enrollment.
What RADIUS-Based MFA Actually Adds to FortiGate
A third-party RADIUS proxy doesn’t just replicate FortiToken functionality at a different price point — it changes what’s possible:
Hardware token flexibility. FortiToken 200-series tokens are purpose-built for Fortinet and activated through FortiGuard. Third-party RADIUS MFA supports any OATH TOTP, HOTP-compatible token, including programmable NFC tokens that can be re-seeded and reassigned when employees leave. The Protectimus Slim NFC, for example, is a card-format programmable OATH token — functional equivalent to FortiToken 200, but re-programmable.
Air-gapped environments. FortiToken Mobile activates tokens through FortiGuard (Fortinet’s cloud service). Air-gapped networks that can’t reach FortiGuard need the FortiToken 200CD with encrypted CD activation, or a RADIUS proxy running entirely on-premises.
Multi-vendor coverage. A single RADIUS MFA deployment covers FortiGate alongside Cisco ASA/FTD, Palo Alto GlobalProtect, SonicWall, OpenVPN, and other RFC 2865-compliant clients. One user enrollment, one admin console, one audit log.
For the full MFA for FortiGate implementation — including step-by-step RADIUS configuration and a detailed comparison with FortiToken — see the dedicated page. For the broader VPN MFA architecture covering multiple vendors from a single deployment, see MFA for VPN. For hardware token options compatible with RADIUS-based FortiGate MFA, see hardware TOTP tokens.
Which Approach Fits Which Scenario
FortiToken Mobile makes sense when:
- You have a single FortiGate appliance and a stable user base
- All users have smartphones (no hardware token requirement)
- No other VPN or network devices need MFA
- You prefer a perpetual license model and expect low user turnover
FortiToken + FortiAuthenticator makes sense when:
- You have multiple FortiGate units across locations
- You want centralized management within the Fortinet ecosystem
- You’re already invested in Fortinet infrastructure across the board
Third-party RADIUS MFA makes sense when:
- You have multiple FortiGate units but don’t want a separate FortiAuthenticator appliance
- You need MFA for non-Fortinet devices alongside FortiGate
- You need hardware token support beyond Fortinet’s token line
- You need centralized MFA across multiple FortiGate appliances without appliance-bound licensing
- You need on-premises deployment without FortiGuard cloud dependency for token activation
The numbers favor different approaches depending on which of these variables applies to your environment. The FortiToken perpetual license is genuinely cost-effective for simple, single-appliance deployments. It becomes more expensive and more operationally complex as the infrastructure grows.
Subscribe To Our Newsletter
Join our mailing list to receive the latest news and updates from our team.
Subscribe To Our Newsletter
Join our mailing list to receive the latest news and updates from Protectimus blog.
You have successfully subscribed!