Skip to main content
HT_JDC
New Member
September 15, 2024
Solved

VXLAN under SDWAN IPsec over NAT

  • September 15, 2024
  • 4 replies
  • 2020 views

Hello Experts,

 

In site-to-site VXLAN under SDWAN IPsec over NAT,

does Fortigate at NAT outside need to specify WAN IP address of the other Fortigate?

Here is my network environment.

 

   Inside    Outside 

|---| -- NAT1 -- |--------| --- |---|
|FG1|            |Internet|     |FG2|
|---| -- NAT2 -- |--------| --- |---|

   Inside    Outside 

 

Both network I/F of FG2 are configured as "Dialup User".
FG2 does not know WAN IP address of FG1 before FG1 connects to FG2.
In order to establish VXLAN between FG1 and FG2, after getting FG1 network I/F IP addresses
I needed to specify static route to the IP addresses at FG1.

 

Are there any other solutions?

 

Any comments are appreciated.

Best answer by Hatibi

Yes, in this case you need to specify the tunnel IP address of the other FGT.

4 replies

Hatibi
Staff & Editor
Staff & Editor
September 16, 2024

The guide states the following:

https://docs.fortinet.com/document/fortigate/7.6.0/administration-guide/247006/vxlan-over-ipsec-using-a-vxlan-tunnel-endpoint

 

 

 

The hub FortiGate inserts a reverse route pointing to newly established tunnel interfaces for any of the subnets that the spoke FortiGate's source quick mode selectors provides. This is why you should set the tunnel IP address here.

 

Might be worth to use dynamic routing:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Dynamic-dial-up-VPN-with-OSPF/ta-p/197156

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-deploy-dial-up-IPsec-VPN-in-SDWAN-using-BGP/ta-p/316953

HT_JDC
HT_JDCAuthor
New Member
September 16, 2024

Hello SX11,

Thanks for your comments.

I looked at all URLs.

Excuse me again. Thus, I should specify the remote tunnel address at FG2 (NAT outside).

Is it correct?

Any comments are appreciated.

Hatibi
Staff & Editor
HatibiAnswer
Staff & Editor
September 16, 2024

Yes, in this case you need to specify the tunnel IP address of the other FGT.

HT_JDC
HT_JDCAuthor
New Member
September 16, 2024

Hello sx11,

Thanks for your reply. I understood it.

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!