VXLAN Setup on 7.0 Advice sought.
Hi All,
I have a client who we are moving VMware ESX from a Data Centre to the head office. They have FGT's at both ends. Soon to be v7
And we have about 2 VLAN's at the DC we wish to have replicated over to the head office.
Head Office: 192.168.2.0/24
Data Centre: 192.168.100.0/24 (Default VLAN)
Data Centre: 192.168.101.0/24 (VLAN 101) - VMware Vmotion
The customer already has an existing IPSEC tunnel to the Data Centre from the Head Office and vice versa.
If I add the VXLAN as per the cookbook. I am assuming this will break the routing of the existing IPSEC tunnel? I am also assuming that I can run multiple VLAN's over VXLAN?
So should I tell the Head Office Fortigate to route 192.168.100.0/24 & 192.168.101.0/24 to the local VXLAN interfaces? and remove the configuration for the existing IPSEC tunnels?
And when I get this setup, do I just leave the default gateway at the same at both sites? And when a device wants internet access from Head Office on the VXLAN, does it route it over the IPSEC to go out the default gateway at the DC?
I am trying to avoid any potential snags, before deployment. So if anyone has advice/experience that may help. I would be happy to hear it.
Andy
