Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Andrade_Narcis
New Contributor

FortiSwitch Discovery over IPSEC VPN Tunnel

Can Fortilink over Layer 3 on IPSEC VPN Tunnels be used for Branch Site FortiSwitch Discovery and Configuration

3 REPLIES 3
gfleming
Staff
Staff

Yes indeed. However no L3 routing will be handled by FortiGate in this case. It will just be L2/VLAN mgmt. You'll need a local L3 device.

 

https://docs.fortinet.com/document/fortiswitch/7.2.4/fortilink-guide/801182/fortilink-mode-over-a-la...

Cheers,
Graham
Andrade_Narcis

Hi Graham, 

The Customer Topology is as follows:

           Branch Site                              WAN                                Head Office

FortiSwitch -> ISP Fortigate -> ISP IPSEC VPN -> ISP Fortigate -> ISFW  Fortigate -> FortiSwitch

 

Branch Site Fortigate creates a VPN Tunnel to HeadOffice; are you saying that I'll need to assign a management ip on the Branch Site Switch and advertise in IPSEC

 

gfleming

Read the doc. You just need the FortiLink interface to be reachable across the L3 network.

Cheers,
Graham
Labels
Top Kudoed Authors