Skip to main content
Toshi_Esumi
SuperUser
SuperUser
April 21, 2020
Solved

VLAN inside VXLAN with 6.2.3

  • April 21, 2020
  • 12 replies
  • 13263 views

Did anyone make below set up work successfully with 6.2.3? I'm just testing with relatively simple set up: FG50E -- FG30E direct connection and trying to connect vlan 100 network on both ends. Likely my test environment is causing some issues. But once I drop the vlan subinterface and use it's parent interface without vlan tag, it just works end to end. Sniffing shows ARP requests arrive at local vlan100 subinterface, but never goes over to the other side.

https://docs.fortinet.com...4150/vlan-inside-vxlan

 

 

 

    Best answer by ispcolohost

    I'm considering abandoning the attempt and moving to a linux-based vxlan bridge downstream of the Fortigate.  The issue on the Fortigate side is it forces you into software switch, physical port, etc. so you lose physical redundancy, port aggregation, and throughput is going to be severely limited by fowarding on the CPU.  Their vxlan implementation seems to be a sloppy afterthought.  If you have something else doing the encapsulation that can do it efficiently, and the Fortigate sticks to ipsec in hardware (plus lacp and HA), you can get the thoughput and redundancy back.

    12 replies

    tanr
    New Member
    April 22, 2020

    Hi Toshi,

     

    Did you get any further with this?  I've been wanting to test this as well, but don't have a second lab FortiGate and would like to hear a success story before I test this on production over IPsec.

    Toshi_Esumi
    SuperUser
    SuperUser
    April 22, 2020

    So far I haven't figured out a way for this 6.2 new feature (to me the whole reason to have VXLAN) to work, while 6.0 supported part works fine. That's why I posted the question if anyone had made it work. I'm feeling the description in Cookbook is missing something important. If no reply from others, I will need to move my current test environment to another FGT that has a support then open a ticket at TAC to get help.

     

    Toshi

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.