Skip to main content
RobertoS
New Member
July 17, 2026
Question

FortiClient Enterprise Linux IPsec disconnects exactly ~9 seconds after successful connection (RHEL 9 / Ubuntu 24.04)

  • July 17, 2026
  • 5 replies
  • 94 views

Hi everyone,

We are troubleshooting what appears to be a Linux-specific FortiClient Enterprise issue and I would like to know if anyone has experienced something similar.

Environment:

  • FortiClient Enterprise Linux 7.4.7 build 5438
  • FortiGate 7.4.x
  • IPsec VPN (IKEv2)
  • RHEL 9.x and Ubuntu 24.04

Behaviour:

  • VPN authentication succeeds.
  • Tunnel is established successfully.
  • Approximately 9 seconds later the VPN disconnects.
  • The timing is very consistent (always around 9 seconds).

What we have already verified:

  • Same FortiGate configuration works perfectly with FortiClient Enterprise for Windows.
  • Reproduced on both RHEL 9 and Ubuntu 24.04.
  • Reproduced on both physical and virtual machines.
  • Reproduced on x86_64 (and also ARM64 with 7.4.7 where supported).
  • Client is not registered to EMS.
  • FortiGate logs do not show authentication failures, DPD timeout, IKE negotiation errors or peer-initiated disconnects.
  • The Linux client appears to terminate the session locally after the tunnel has already been established.

We are currently testing older Linux releases (7.4.6 / 7.4.5 where available) to determine whether this is a regression.

Has anyone experienced a deterministic disconnect after about 9 seconds on Linux?

Any information, workaround, or TAC feedback would be greatly appreciated.

5 replies

AEK
SuperUser
SuperUser
July 17, 2026

Do you mean this behavior was noticed for clients that are not EMS registered?

Does it actually work for registered clients?

Also it is a good idea to try older versions like 7.4.6 and 7.4.5.

AEK
RobertoS
RobertoSAuthor
New Member
July 20, 2026

The client has not yet been registered because the VPN is needed to access the EMS server, which is not exposed to the internet. Versions 7.4.5 and 7.4.6 do not support Linux IPsec IKEv2. We are unable to register clients without the VPN..

AEK
SuperUser
SuperUser
July 20, 2026

Then is the behavior the same when you connect with the free FortiClient version?

AEK
RobertoS
RobertoSAuthor
New Member
July 21, 2026

The free version for Linux does not support IPsec IKEv2, so I can’t test it. However, I’ve tried Red Hat, Ubuntu and Fedora, and I’ve encountered the same problem on all of them. On Windows, on the other hand, it works without any issues, even without the licensed client from EMS. When using linux Strong Swarm, the connection is stable and problem-free.

AEK
SuperUser
SuperUser
July 21, 2026

Hi Roberto

I found no such known issue in 7.4.7.

https://docs.fortinet.com/document/forticlient/7.4.7/linux-release-notes/226409/existing-known-issues

In such case I’d try different IPsec settings (change both FGT and FCT sides), for example by testing different DH groups and different Encryption/Authentication pairs (the issue may be related to this), and in case it still doesn’t work I’d open a ticket.

AEK
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.