Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
SSUPPORT
New Contributor

AWS GWLB cross AZ

In reference to the below article.

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configuring-GEneric-NEtwork-Virtualization...

The below traffic config 

config system geneve

    edit "consumer"             

        set interface "port1"

        set type ppp    <- case where the internal packet has no Ethernet Header.

        set remote-ip 10.4.1.22 <- GENEVE tunnel remote peer IP address.            

    next

end

 

1. In the above config , when we deploy customer VPC in 2 AZs and with 2 GWLBendpoints

 

2. What do we configure on the GENEVE interface as remote iP , will this be the GWLB IP address from the same subnet as Security VPC  or the Remote GWLBe endpoint IP address

 

3 REPLIES 3
Anthony_E
Community Manager
Community Manager

Hello SSUPPORT,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Anthony-Fortinet Community Team.
Anthony_E
Community Manager
Community Manager

Hello SSUPPORT,

 

We are still looking for someone to help you.

We will come back to you ASAP.


Regards,

Anthony-Fortinet Community Team.
saneeshpv_FTNT

Hi @SSUPPORT ,

 

Not sure if you have seen this article.

 

https://aws.amazon.com/blogs/networking-and-content-delivery/integrate-your-custom-logic-or-applianc...

 

Anyway, based on the flow explained in this article, your Security appliance (ex: FGT here) should be configured the Remote IP as the IP address of GWLB and not GWLBE. One GWLB can be connected to many GWLBEs.

 

Not sure if this clarifies your questions. If not please open a case with Fortinet Support for additional help.

 

Best Regards,
Saneesh

Labels
Top Kudoed Authors