Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Cajuntank
Contributor II

VXLAN discussion/design questions?

This is my first foray into the need for VXLAN and have some questions. My current site has a L3 Aruba switch, which handles my internal VLANs, an egress VLAN connecting to my FortiGate which connects to both a private WAN circuit to my data center (which in turn, provides Internet) and a backup Internet circuit for Internet failover and the IPSEC VPN spoke to hub (data center).

 

Bought new building that we will be moving to, so want to implement VXLAN so I can use the same VLANs and subnets for all the new equipment going in so when we do actually move, it will be an easier transition. So the VXLAN config will be a temporary situation (no more than 6 months is my guess).

 

From a design perspective, my idea is to implement the same low cost Internet "backup" at the new site, but it will be the main Internet connection until time gets closer for the move to add the higher dollar private WAN circuit as the primary. I will establish a IPSEC VPN connection between the two sites directly (so not even going to attempt to go through data center). I have looked at the config example of what I have to do at the Aruba level for VXLAN, but my question is, since the VLANs are all hanging off the of the Aruba L3 switch, is there even the need to also do any kind of VXLAN on the FortiGate?

1 Solution
ebilcari
Staff
Staff

If this will involve only two sites and the Aruba switches can handle VXLAN and work as VTEPs, the FGT don't have to participate. FGT will only see it as a UDP traffic on port 4789.

The only part that needs careful planning is the MTU, since you are planning to also have IPSec you will need a bigger MTU (1600) if the ISP allows it. You can also refer to this old discussion here.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.

View solution in original post

3 REPLIES 3
Jean-Philippe_P
Moderator
Moderator

Hello Cajuntank, 

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible. 

 

Thanks, 

Jean-Philippe - Fortinet Community Team
ebilcari
Staff
Staff

If this will involve only two sites and the Aruba switches can handle VXLAN and work as VTEPs, the FGT don't have to participate. FGT will only see it as a UDP traffic on port 4789.

The only part that needs careful planning is the MTU, since you are planning to also have IPSec you will need a bigger MTU (1600) if the ISP allows it. You can also refer to this old discussion here.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
Cajuntank

That was my gut thought reaction, but wanted to run it by someone to make sure or see if maybe I was just missing something as again, this will be my first VXLAN config need. I doubt I will have any kind of ability to adjust the MTU on the ISP side of things, but I will ask to see if possible. Thank you.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors