Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
dtonkin
New Contributor II

VXLAN

Hi, just after some help from anyone who has had some experience with VXLAN.

I setup a VXLAN a while ago which worked fine but now has stopped passing traffic?  the ipsec tunnel is up but can only see traffic either side, ie not traversing the L2 VXLAN, it's a fairly simple setup, diag attached

Any help/suggestions appreciated.

Dave

1 Solution
dtonkin
New Contributor II

Hi resolved this VXLAN issue by using set intra-switch-policy implicit in the vxlan softswitch config.

View solution in original post

4 REPLIES 4
emnoc
Esteemed Contributor III

The cli cmd diag debug flow is your friend. I would run that and also diag sniffer packet  the interface to see if packest are being sent or recv Also review closely your diag vpn tunnel list details to see if encryt/decrypt is happening and you have a valid SPI in/out.

 

 

Ken Felix

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
boneyard
Valued Contributor

which version FortiOS? 6.0 had an annoying issue where VXLAN traffic failed after a restart.

dtonkin
New Contributor II

Hi, we're on v 6.2

dtonkin
New Contributor II

Hi resolved this VXLAN issue by using set intra-switch-policy implicit in the vxlan softswitch config.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors