Hello,
I am experiencing a strange issue with FortiClient VPN 7.4 and FortiGate 7.6
I've configured an IPSec Dialup server on specific public IP using certificates + xauth + no split tunnel (using aggressive mode).
Connection is fine and works as expected, but when I click on Disconnect (on client side), I got the disconnection on client but on fortigate connection is still shown as ACTIVE until dpd kill it. I checked on client side using wireshark but cannot see any packet going out when clicking on disconnect.
Is this the right behavious or I missed something?
Thanks
hello
please refer to the document related to Dead Peer Detection (DPD)
If there is incoming data traffic on ANY phase 2 selector from the IKE peer, FortiGate WILL NOT send DPD_R_U_THERE under any circumstance. 
 
If phase1 configuration has 'set dpd on-idle': FortiGate will send DPD_R_U_THERE if it does not receive any IPsec (data) traffic from the remote peer. If multiple IPsec (phase 2) selectors are configured but only one has incoming data traffic, no DPD will be sent. If no IPsec SA is available, FortiGate WILL send DPD. 
 
If phase1 configuration has 'set dpd on-demand': This is the default configuration. The behavior is like DPD 'idle', but with the additional requirement that FortiGate will only send the DPD_R_U_THERE if it has also sent data traffic over the IPsec tunnel during the previous DPD interval.
The device does not check whether the incoming traffic is related to the outgoing traffic. If there is incoming traffic on one phase2 selector and outgoing on another, FortiGate WILL NOT send DPD_R_U_THERE. If no phase2 selector is available, FortiGate WILL NOT send DPD. 
Hi Shashwati,
thanks for reply and for link about dpd.
My issue is not related to dpd but to the missing disconnect from client to fortigate.
Let me explain better:
1) I start connection from forticlient IPSec to Fortigate
2) Connection is esablished and I see it fortigate management.
3) THen I hit "disconnect" on client
4) After a couple of seconds client report Disconnected
If I then look at fortigate managemnet, I still see the connection as established. COnnection closes only after DPD (and fortigate report this).
I see this when I use a "full tunnel" vpn.
If VPN is a split-tunnel, then hitting disconnect on client causes both closure on client and fortigate.
I think that when establishing a full tunnel disconnect packets are sent WITHIN the tunnel (I see them with wireshark sniffing the virtual adapter).
I guess I did something wrong because I can't believe this is the default behaviour .
Thanks
Thank you so much for sharing link.
It's great to hear that the FortiClient IPSec VPN remains connected! A stable VPN connection is essential for maintaining productivity and secure access to resources. Fortinet’s reliability in this regard really stands out. If there are any tips or tweaks you've applied for optimization, sharing them could be helpful to others in the community to check more
@ATosI5 wrote:Hello,
I am experiencing a strange issue with FortiClient VPN 7.4 and FortiGate 7.6
I've configured an IPSec Dialup server on specific public IP using certificates + xauth + no split tunnel (using aggressive mode).
Connection is fine and works as expected, but when I click on Disconnect (on client side), I got the disconnection on client but on fortigate connection is still shown as ACTIVE until dpd kill it. I checked on client side using wireshark but cannot see any packet going out when clicking on disconnect.
Is this the right behavious or I missed something?
VPNs are used for different purposes - one of them might be to gamble or something similar. If this is what you need a VPN for, then you should reconsider your service. You might like magyar online casino - where you don't need any VPN or other third-party services.
Thanks
Ensure that your FortiClient is properly sending the disconnect signal to the FortiGate. Sometimes, settings on the client side might prevent proper session teardown.
Can you please elaborate on this? I am having a similar issue, but in my research, I am not finding any setting that would appear to communicate this to the Fortigate.
 
					
				
				
			
		
| User | Count | 
|---|---|
| 2678 | |
| 1412 | |
| 810 | |
| 704 | |
| 455 | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.