VXLAN under SDWAN IPsec over NAT
Hello Experts,
In site-to-site VXLAN under SDWAN IPsec over NAT,
does Fortigate at NAT outside need to specify WAN IP address of the other Fortigate?
Here is my network environment.
Inside Outside
|---| -- NAT1 -- |--------| --- |---|
|FG1| |Internet| |FG2|
|---| -- NAT2 -- |--------| --- |---|
Inside Outside
Both network I/F of FG2 are configured as "Dialup User".
FG2 does not know WAN IP address of FG1 before FG1 connects to FG2.
In order to establish VXLAN between FG1 and FG2, after getting FG1 network I/F IP addresses
I needed to specify static route to the IP addresses at FG1.
Are there any other solutions?
Any comments are appreciated.
