Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Fabio
Contributor

LAN over WAN tunnel

Hello, everyone,
I would like some advice on how I could make a bridge of a LAN subnet over a WAN connection.
I would like to use a GRE tunnel that succeeds through an IPSEC connection between the two FGTs the ability to reach hosts from the other site that share the same subnet. However, I have not found many examples of this configuration.
Instead, I have seen a solution called Lan Extension that uses an IPSEC tunnel where VxLANs are carried. It is a solution that I see as very complicated to put on .
Do you have experiences for this kind of needs and scenarios ?
Thanks

 

Fabio

Fabio
Fabio
1 Solution
Fabio
Contributor

Hi guys,
I found an article that did just my purpose.

https://docs.fortinet.com/document/fortigate/7.4.3/administration-guide/184150/vlan-inside-vxlan
Even without the Ipsec tunnel.
Was very useful and easy to implement because it is also applicable to our system composed of Vlan ( 802.1q) 

 

In this article, it talks about the fact that within the switch software, interfaces in 802.1q is not supported:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Building-a-Layer-2-VPN-with-VxLAN-over-IPs...

 

Thank @hbac for inspiration.

Fabio

View solution in original post

Fabio
4 REPLIES 4
Sx11
Staff
Staff
AEK
SuperUser
SuperUser

Hello Fabio

I'm not network expert but I know only VxLAN can do that.

https://docs.fortinet.com/document/fortigate/7.4.3/administration-guide/38079/vxlan

AEK
AEK
hbac
Staff
Staff

Hi @Fabio,

 

I believe VXLAN is the only option. Please refer to https://community.fortinet.com/t5/FortiGate/Technical-Tip-Basic-VXLAN-over-IPsec-configuration/ta-p/...

 

However, it is possible to use NAT to avoid overlapping subnets: https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-configure-an-IPsec-tunnel-with-Over...

 

The simplest way is not to use the same subnet for both sides. 

 

Regards, 

Fabio
Contributor

Hi guys,
I found an article that did just my purpose.

https://docs.fortinet.com/document/fortigate/7.4.3/administration-guide/184150/vlan-inside-vxlan
Even without the Ipsec tunnel.
Was very useful and easy to implement because it is also applicable to our system composed of Vlan ( 802.1q) 

 

In this article, it talks about the fact that within the switch software, interfaces in 802.1q is not supported:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Building-a-Layer-2-VPN-with-VxLAN-over-IPs...

 

Thank @hbac for inspiration.

Fabio
Fabio
Labels
Top Kudoed Authors