Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
TopJimmy
New Contributor

Tag (802.1q) VLAN' s through IPSec tunnel

Our corp site is connected to a remote site and the need to have the same VLAN' s be live on both ends has arisen. Is it possible to tag a few VLAN' s from one site to another across the IPSec tunnel. Both ends are FortiGates running 4.3.14
-TJ
-TJ
4 REPLIES 4
emnoc
Esteemed Contributor III

This questions comes up once very few blue moons. The ipsec ona fortigate is a layer3 function ( network/routing ), what you need is either a L2TPv3 or MPLS or even GRE-bridging. None of the above are available over a IPSEC. What you might want to do; create two internet devices that bridges the networks between siteA &B and carry this traffic over the ipsec tunnel +FGT. The real question; what' s driving the need for the same subnet available at the 2 sites? I would guess this is a poor design that would lead to further complications down the road.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
TopJimmy
New Contributor

Disaster recovery. We are a VMWare heavy IT department and all of our data/servers are replicated nightly to a DR location (remote site). In the event of a disaster or even a server failure, our goal is bring up the server(s) in question at the DR without having to re-ip them. I' m open to suggestions if you have any. This is new territory for me.
-TJ
-TJ
emnoc
Esteemed Contributor III

Are you using SRM? and if not why ? and that would cover your DR deployment.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
TopJimmy
New Contributor

Sorry...forgot to mention we' re using EMC' s Recover Point Appliance to replicate our SAN which still wouldn' t allow the same subnets at both ends.
-TJ
-TJ
Labels
Top Kudoed Authors