Created on
09-22-2025
07:21 AM
Edited on
09-26-2025
09:28 AM
By
Stephen_G
| Description | This article describes an issue related to the hostname, which is missing on the logs of the DHCP server, when users connect via IPsec VPN using IKEv2 and SAML, and FortiGate is configured as a DHCP relay. |
| Scope | FortiGate. |
| Solution |
The devices are connected as follows:
Client (FortiClient) --- (connected via IPsec VPN to FortiGate) --- FortiGate (DHCP relay) - DHCP server.
The FortiGate configuration used for this issue is:
config vpn ipsec phase2-interface config sys interface config system settings
When the clients connect trough IPsec VPN using IKEv2 and SAML, the connection is successful. However, the hostname is not shown on the DHCP server logs as shown in the image below.
The hostname is sent using Option 12, as defined in RFC 2132 (screenshot below is taken from) RFC 2132: https://www.ietf.org/rfc/rfc2132.txt.
This behavior is noticed in environments with IPsec VPN using IKEv2 and SAML. This is currently not supported on FortiClient, and it is addressed to the engineering team through NFR: 1151961. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.