Trying to extend a VLAN via VXLAN between two FortiGate 200G units over an IPsec tunnel. ARP and broadcast traffic get through fine, but unicast (ICMP) doesn’t. ARP tables look good, VXLAN UDP (port 4789).
Anyone dealt with a similar setup or have tips to debug?
Want me to tailor it more for Fortinet pros or add some tags to get extra traction?
you can do some check with these commands,
diagnose sys vxlan fdb list <VXLAN_interface>
diagnose sys vxlan fdb stat <VXLAN_interface>
diagnose netlink brctl name host <switch_interface>
doing a sniffer/tcpdump, can you confirm that on the remote FGT ICMP arrives? maybe you need some fw rules to allow traffic if switch policy is set to explicit.
User | Count |
---|---|
2571 | |
1365 | |
796 | |
653 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.