Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
nothingel
New Contributor III

Bridging / layer2 vpn

Is it possible to create a layer 2 or bridging VPN between two Fortigates? I am well-versed in interface-mode layer 3 IPsec VPNs on Fortigates where each side of the tunnel has their own subnet. However, my current problem would best be solved by bridging a very small remote network with the main network (seeing all broadcasts, using the same IP scheme, etc). As an example, I am looking for a way to duplicate the functionality of OpenVPN' s " tap" bridge mode. Thanks!
8 REPLIES 8
Carl_Wallmark
Valued Contributor

Hi, I dont think its possible as you describe it, i have searched for this as well. But there is a way to allow a few addresses from the same subnet to be on both sides, and its transparent. the word to search for is " proxy-arp" at kb.fortinet.com

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
emnoc
Esteemed Contributor III

What you will need is a l2 MPLS VPN or L2tpv3, neither are supported within the fortigate or any other firewall that I can think of. What are you trying to accomplished or achieve with bridging over to networks? Do you have network overlaps ?

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
FortiRack_Eric
New Contributor III

you can create a VPN between 2 Fortigate (vdoms) in transparant mode using policy based VPN. That' ll do the trick.

Rackmount your Fortinet --> http://www.rackmount.it/fortirack

 

Rackmount your Fortinet --> http://www.rackmount.it/fortirack
Carl_Wallmark
Valued Contributor

Eric: is that possible ? i been searching for a way to do this.. so the same subnet can be on both sides of the VPN tunnel ? (same broadcast domain)

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
nothingel
New Contributor III

Can you elaborate a little more on the high level concept of a transparent mode VPN? Would broadcast traffic (including ARP) traverse? To answer the earlier question, there is a building on the property that cannot be reached via wire or wireless without extreme cost due to environmental constraints. However, cable/dsl already reaches the other building. Due to the very small number of clients, the desire is to logically extend the needed networks using the concept of bridges if at all possible. Yes, I do think MPLS would do the trick but that doesn' t seem to be an option. I' m toying with the idea of OpenVPN in " tap" mode but there' s certain drawbacks too. In the end, I may have to give up and use traditional layer 3 routed segments. It' s too bad the Fortigate soft switch cannot add IPsec interfaces as members. Thanks for the thoughts thus far!
FortiRack_Eric
New Contributor III

Nope, sorry missed the part that both subnets should be the same. you can do nat on this, but that probably won' t meet the requirement. I hope you' re not falling in the trap that some SAN supplier wants the same subnet for both for replication and failover purposes. From a network and security standpoint I won' t go for this. To subnets on the same subnet. It' s asking for problems. A recipe for disaster.

Rackmount your Fortinet --> http://www.rackmount.it/fortirack

 

Rackmount your Fortinet --> http://www.rackmount.it/fortirack
emnoc
Esteemed Contributor III

ditto Your best bet is to get out of bridging and make unique L3 subnets or NAT the remote network. if it' s a network that you own/admin, then re-address them and do it smarter & not harder.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
nothingel
New Contributor III

Just a quick update -- L2TPv3 between two Cisco routers works great. There' s a few gotchas with servers on the Internet that block all ICMP, thus breaking PMTU but fortunately there' s several workarounds. I sure wish Fortigate supported L2TPv3. It' s a good tool in the right situation.
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors