PCNSE
NSE
StrongSwan
FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C
FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C
All other big vendors can do this, and there is a way to do this on a fortigate as well, but it is far from perfect,Who' s a big vendor that can do this ? Cisco ? Juniper ? and carry l2 network across a layer3 vpn-ipsec
PCNSE
NSE
StrongSwan
so you tell us that 0.0.0.0/0 as src/dst and proxy-arps will handle l3 broadcats for discovery items? i.e netbios lookups? dhcp ?No, that will probably not work, it will only work with IP to IP, for example: Site1 192.168.1.0/24 -------FG_tunnel---------Site2 192.168.1.0/24 If 192.168.1.1 is on site 1 and 192.168.1.2 is on site 2. These IP´s can talk to each other without NAT between them. If you configure proxy-arp. For example, Cisco has the " pseudowire" in L2TPV3 which will allow a full L2 network over IPSEC. Juniper has the ability as well. Hell, even OPENVPN can do this. (http://i2p.net.in.tum.de/)
FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C
For example, Cisco has the " pseudowire" in L2TPV3 which will allow a full L2 network over IPSEC. Juniper hasBut pseudowire is not ipsec & has nothing todo with IPSEC, so that' s why I had to challenge that statement that you made by major " Vendors" , and I can' t speak on SRX but a MX probably will not let you do pseudowire over a ipsec, and the same for a cisco ASA. So that rules out them 2 as major Vendors
 I would like to see some one with an actual working config of a L2VPNv3 or even MPLS over a ipsec tunnel. It would be interesting if not for alot of  over head and pMTU/MSS issues.
 
 btw, some one has a proposal/patent out for L2VPN encryption iirc. But I' m not sure if any pseudowire are using ipsec from a practical concept.
 
 FWIW: You can always terminate the L2VPNv3 behind the firewalls and then run that thru, but be advise of the over-head and use  mtu or tcp-mss-adjustment to counter the path MTU.
 I would like to see some one with an actual working config of a L2VPNv3 or even MPLS over a ipsec tunnel. It would be interesting if not for alot of  over head and pMTU/MSS issues.
 
 btw, some one has a proposal/patent out for L2VPN encryption iirc. But I' m not sure if any pseudowire are using ipsec from a practical concept.
 
 FWIW: You can always terminate the L2VPNv3 behind the firewalls and then run that thru, but be advise of the over-head and use  mtu or tcp-mss-adjustment to counter the path MTU.
					
				
			
			
				PCNSE
NSE
StrongSwan
FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C
 
					
				
				
			
		
| User | Count | 
|---|---|
| 2679 | |
| 1412 | |
| 810 | |
| 704 | |
| 455 | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.