Skip to main content
kdharan
Staff
Staff
March 25, 2026

Technical Tip: FortiClient 7.4.4 VPN Settings: IKEv1 Deprecation and Address Assignment Limitations

  • March 25, 2026
  • 0 replies
  • 1174 views
Description This article describes the VPN configuration changes and limitations introduced in FortiClient version 7.4.4. Specifically, it outlines the removal of IKEv1 support and the restricted options available for IPsec VPN address assignment.
Scope FortiClient version 7.4.4
Solution

FortiClient 7.4.4 introduces significant changes to the IPsec VPN configuration framework. Administrators and users should be aware of the following modifications:

 

  1. IKEv1 protocol deprecation.

 

Starting with version 7.4.4, FortiClient no longer supports Internet Key Exchange version 1 (IKEv1) for IPsec VPN tunnels.

  • Impact: IPsec VPN configurations that rely on IKEv1 will fail to establish a connection.

  • Requirement: All IPsec VPN connections must be configured to use IKEv2 (Internet Key Exchange version 2).

Attempting to connect to a VPN gateway configured only for IKEv1 will result in a negotiation failure.

 

  1. Address assignment limitations.

When configuring an IPsec VPN in FortiClient 7.4.4, the options for address assignment have been streamlined. The following settings are no longer supported:

  • Manually Set: The option to manually specify a static virtual IP address for the VPN adapter is unavailable.

  • DHCP over IPsec: The method of obtaining an IP address via DHCP over the IPsec tunnel is not supported.


FCTIKE.png

Current supported method:
The only available method for address assignment in this version is Mode Config. The VPN gateway must be configured to assign an IP address to the FortiClient endpoint using Mode Config.

 

Solution / workaround:

To ensure successful VPN connectivity with FortiClient 7.4.4:

  1. Update VPN gateway configuration: Ensure the remote FortiGate or third-party VPN gateway is configured to use IKEv2.

  2. Configure mode config: On the VPN gateway, verify that Mode Config is enabled and configured to assign IP addresses to clients. Remove any dependency on static address assignment or DHCP over IPsec for these clients.

  3. Recreate VPN profiles: If upgrading from an older version, it is recommended to recreate the VPN connection profile in FortiClient 7.4.4 rather than relying on imported configurations that may contain unsupported settings.