This is my first foray into the need for VXLAN and have some questions. My current site has a L3 Aruba switch, which handles my internal VLANs, an egress VLAN connecting to my FortiGate which connects to both a private WAN circuit to my data center (which in turn, provides Internet) and a backup Internet circuit for Internet failover and the IPSEC VPN spoke to hub (data center).
Bought new building that we will be moving to, so want to implement VXLAN so I can use the same VLANs and subnets for all the new equipment going in so when we do actually move, it will be an easier transition. So the VXLAN config will be a temporary situation (no more than 6 months is my guess).
From a design perspective, my idea is to implement the same low cost Internet "backup" at the new site, but it will be the main Internet connection until time gets closer for the move to add the higher dollar private WAN circuit as the primary. I will establish a IPSEC VPN connection between the two sites directly (so not even going to attempt to go through data center). I have looked at the config example of what I have to do at the Aruba level for VXLAN, but my question is, since the VLANs are all hanging off the of the Aruba L3 switch, is there even the need to also do any kind of VXLAN on the FortiGate?
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
If this will involve only two sites and the Aruba switches can handle VXLAN and work as VTEPs, the FGT don't have to participate. FGT will only see it as a UDP traffic on port 4789.
The only part that needs careful planning is the MTU, since you are planning to also have IPSec you will need a bigger MTU (1600) if the ISP allows it. You can also refer to this old discussion here.
Hello Cajuntank,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
If this will involve only two sites and the Aruba switches can handle VXLAN and work as VTEPs, the FGT don't have to participate. FGT will only see it as a UDP traffic on port 4789.
The only part that needs careful planning is the MTU, since you are planning to also have IPSec you will need a bigger MTU (1600) if the ISP allows it. You can also refer to this old discussion here.
That was my gut thought reaction, but wanted to run it by someone to make sure or see if maybe I was just missing something as again, this will be my first VXLAN config need. I doubt I will have any kind of ability to adjust the MTU on the ISP side of things, but I will ask to see if possible. Thank you.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1714 | |
1093 | |
752 | |
447 | |
232 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.