Skip to main content
hpenmetsa
Staff
Staff
January 22, 2026

Technical Tip: FortiClient VPN is connected and disconnected endpoint event logs are not displaying on the FortiGate

  • January 22, 2026
  • 0 replies
  • 589 views
Description

This article describes that FortiClient VPN connected and disconnected endpoint event logs are not displaying on the FortiGate.

Scope FortiGate, FortiOS v7.4.4, and above.
Solution

While connecting to the VPN from FortiClient, the following endpoint event logs are generated on the FortiGate:
 
Endpoint logs from the FortiGate.
 

FortiClient VPN disconnected.


date=2026-01-05 time=12:57:11 eventtime=1767574631620780523 logid="0107045125" type="event" subtype="endpoint" level="warning" vd="root" logdesc="FortiClient VPN disconnected" ip=10.10.10.1 fctuid="4BC11620EAF544BFBB123D89D98xxxx" sn="FGVMxxxxxxxxx" intf="Dialup_VPN_0" user="UNKNOWN" msg="FortiClient VPN is disconnected.
 

FortiClient VPN connected.


date=2026-01-05 time=12:56:36 eventtime=1767574596964605421 logid="0107045124" type="event" subtype="endpoint" level="warning" vd="root" logdesc="FortiClient VPN connected" ip=10.10.10.1 fctuid="4BC11620EAF544BFBB123D89D98xxxx" sn="FGVMxxxxxxxxxx" intf="Dialup_VPN_0" user="UNKNOWN" msg="FortiClient VPN is connected.
 

From GUI:

 

Screenshot 2026-01-22 142002.jpg


From FortiOS v7.4.4 and above, the endpoint log id (45124 and 45125) 'FortiClient VPN is connected/disconnected' have been removed. These log IDs will no longer be displayed under Endpoint Events.
 
To verify the VPN tunnel up/down status need to check the VPN events.

Log & Report -> System events -> VPN Events.

 

Screenshot 2026-01-22 142539.jpg