Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Alternative
New Contributor

Vxlan and Internet routing

HI,

 

I had to do an extensible networks for disaster recovery (VMs are replicated to another ESXI Host).

I can make it work but if I provide an IP to my Fortigate. I can browse Internet but not all websites.... I have timeouts with certificate error.

 

Are VXLAN designed for these purposes ?

Did someone implement something approching ?


Thanks !

 

Thanks.

1 REPLY 1
akristof
Staff
Staff

Hello,

Yes, you can use associated software-switch as a gateway and go to internet. However, you need to have in mind that with Vxlan MTU is decreased. And this is often a problem, especially with TCP and with TLS applications. So on firewall policy from software-switch to your external interface, you can decrease TCP-MSS values to lower values (you can try multiple like 1400, 1350, etc) and retest:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Setting-TCP-MSS-value/ta-p/194518

Adrian
Labels
Top Kudoed Authors