Skip to main content
nocadn
New Member
October 27, 2022
Question

Vxlan and ip interfaces

  • October 27, 2022
  • 3 replies
  • 1509 views

I have a scenario of 2 fortigates in version 7 and I already have them talking 2 vxlan and the machines in each Fortinet can ping each other.

But I can't put ip to the vlan interfaces, so that the machine behind each firewall can have a connection, if it were the case, outside the firewall,  regards

 

3 replies

Anthony_E
Staff
Staff
October 30, 2022

Hello nocadn,

 

Thank you for using the Community Forum.

I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Regards,

Best Regards
Anthony_E
Staff
Staff
November 1, 2022

Hello,

 

I have found this document:

 

https://docs.fortinet.com/document/fortigate/7.2.1/administration-guide/247006/vxlan-over-ipsec-using-a-vxlan-tunnel-endpoint

 

Could you please tell me if it helps?

 

Regards,

Best Regards
akristof
Staff
Staff
November 1, 2022

Hello,

 

I am assuming that you have gateway IP on your software-switch that is connecting VXLAN VTEP and local vlan. And then, if you want to have 2 gateways, in case something will go wrong with Ipsec tunnel or connection between FortiGates, VRRP should help you.

You will have one virtual gateway IP and if connection between fortigates go down, each local subnet should be able to communicate with internet as local FortiGate should have active VRRP gateway IP.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.