FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Ylli_Seitaj
Staff
Staff
Article Id 411981
Description This article describes an issue related to the hostname, which is missing on the logs of the DHCP server, when users connect via IPsec VPN using IKEv2 and SAML, and FortiGate is configured as a DHCP relay.
Scope FortiGate.
Solution

The devices are connected as follows:

 

Client (FortiClient) --- (connected via IPsec VPN to FortiGate) --- FortiGate (DHCP relay) - DHCP server.

 

The Clients can connect through the IPsec VPN using IKEv2 and SAML, and they also receive the IP address as expected from the DHCP server, but the hostname of the devices is not shown on the logs of the DHCP server:

 

Screenshot_1.png

 

To send the hostname of the clients is used: Option 12, as defined in RFC 2132 (screenshot below is taken from RFC 2132: https://www.ietf.org/rfc/rfc2132.txt).

 

Screenshot_2.png


This behaviour is noticed in environments with IPsec VPN using IKEv2 and SAML. This is currently not supported on FortiClient, and it is addressed to the engineering team through NFR: 1151961.