I also use 802.1q, LAN port isa trunk on the switch
I am able to ping trough the vxlan ipsec tunnel to the devices at the other site so my vxlan configuration works.
But when i try fileservices, webapplications it's not possible.
It has something to do with MTU size but I can 't figure it out. When i lower my MTU size on my laptop everything goes fine. So I would like to set the MTU size of my vxlan-switch higher but thats not allowed.
I get the message 'MTU size is not valid, should be in range of 68 - 1500'
I've had similar problems
try using a laptop with linux and see if you have the same web access problems.
with linux laptop I had behaviors different from laptop windows, I did not understand the reason.
if you use the trunk on the primary and secondary site switches, on the secondary site try to access the interface with the same pvid of the source trunk
however vxlan on ipsec does not support 802.1q.
So you can not pass more vlan even if it seems that at the IP or icmp level there is availability or reachability.
Try to use my configuration and let me know if it works
I have tested it thoroughly without problems.
from my tests in the laboratory it seems to me that apparently the vlan pass correctly on IPSEC, in fact at ICMP level I did not detect problems but when I used the HTTPS protocols I detected problems.
however, the conversation with the fortinet support is attached.
vxlan on ipsec does not support 802.1q.
I did not understand what you mean by: "Also I see you have configured the vxlan remote ip as local loopback IP,
i believe it should be the remote loopback ip"
I have exactly the same question, ICMP also works for me, but other protocols http, fileservices not.
So actually it doesn 't work because we cannot use it if only ICMP works.
What do they mean with 802.1q is not supported with VXLAN over IPSEC?
When I lower MTU on my laptop everything works fine, (I configured my both swich ports as trunks).
At the switch at the other side of the tunnel I am able to put AccessPoints, Client PC's, Printers in differrent vlans and when I lower MTU everything works. But lowering MTUI of every device is not solution so I would like to change MTU setting on vxlan. But I have no idea what and where i should configure it.
I opened a case and keep you posted. Let me know if you guys find anything....
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.