<endpoint_control>As long as it is "online" status (keepalive is being exchanged between FortiGate and FortiClient), the FortiClient trusts the "on-net" status sent from the FortiGate, and this status is a combination of dhcp-on-net and ip-on-net.
<onnet_addresses>
<address>x.x.x.x-y.y.y.y
<address>x.x.x.x/y.y.y.y
</onnet_addresses>
</endpoint_control>