Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
afton
New Contributor

VXLAN over IPsec issue between 2 FortiGate 200G

Trying to extend a VLAN via VXLAN between two FortiGate 200G units over an IPsec tunnel. ARP and broadcast traffic get through fine, but unicast (ICMP) doesn’t. ARP tables look good, VXLAN UDP (port 4789).

Anyone dealt with a similar setup or have tips to debug?

Want me to tailor it more for Fortinet pros or add some tags to get extra traction?

omegle xender
1 REPLY 1
funkylicious
SuperUser
SuperUser

you can do some check with these commands,

 

diagnose sys vxlan fdb list <VXLAN_interface>
diagnose sys vxlan fdb stat <VXLAN_interface>
diagnose netlink brctl name host <switch_interface>

 

doing a sniffer/tcpdump, can you confirm that on the remote FGT ICMP arrives? maybe you need some fw rules to allow traffic if switch policy is set to explicit.

"jack of all trades, master of none"
"jack of all trades, master of none"
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors