Hi,
We have two Sites, Site A and Site B already connected by telephone line(old), so they share the subnet ip address, now we want to have a VPN tunnel as a Backup with two Fortigate on each side, we cannot change the subnet ip address, Configuring Site-to-site IPSec VPN in Central SNAT mode with overlapping subnets doesn't work because this will change to new IPs, which is the best solution for this?
Solved! Go to Solution.
There are many details missing for the context, but not to start a thread of 20 posts, the answer to your question - if both sites have the same subnet but different IPs assigned to hosts in them, VXLAN between Fortigates may do the job, read about it in documentation.
There are many details missing for the context, but not to start a thread of 20 posts, the answer to your question - if both sites have the same subnet but different IPs assigned to hosts in them, VXLAN between Fortigates may do the job, read about it in documentation.
Hi Yurisk, thank you for your response, I tested VXLAN and this works, now it is possible to have the VXLAN as a backup of the LAN connection?
User | Count |
---|---|
2587 | |
1380 | |
796 | |
658 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.