- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Vlan Trunk Over VPN
I have lant to migrate all of virtual machine to new server in different location, and we need to keep same ip address.
The vlan handled by core switch and the core switch connected to the fortinet, in new location i also have same devices and both location have internet connection.
Since the migration will done partially, this need both location should have same ip address, same vlan and can communicate each other.
So can we use VPN in fortinet to transfer Vlan ? In my mind if we can transfer vlan over VPN then the new location will have same vlan and each host on new location can communicate with devices in of location.
IF migration is done for all virtual machine then i can shutdown vlan interface on old location and make new interface vlan on core switch in new location.
Solved! Go to Solution.
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
this would be what you need for L2 networks across locations,
or for multiple vlans
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
this would be what you need for L2 networks across locations,
or for multiple vlans
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
But in my case the vlan handled by core switch. Should i connect one port from core switch as trunk port and connected to the fortinet port? What ip should be assign in this fortinet port?
Created on ‎02-11-2025 05:10 AM Edited on ‎02-11-2025 05:10 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
configure a port in mode access and connect the fortigate port to it.
dont assign any IPs to it, since the switch interface that you would need to create would not make the port be 'visible' for selection alongside the vxlan interface.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
so port in fortinet side is access with no IP and port in core switch as trunk port, am i right?
Created on ‎02-11-2025 05:23 AM Edited on ‎02-11-2025 05:23 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
if you want to transport multiple vlans, trunk would be the case and on the Forti side you would need to create subinterfaces to tag the traffic with appropiate vlans.
if you only need a single vlan, then the port on the sw side should be in access vlan X.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
understood, so if i want transfer 2 vlan then i must create 2 subinterface on fortigate. Right?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
you are correct.
