Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
JumpingNerd
New Contributor

VXLAN Setup on 7.0 Advice sought.

Hi All, 

 

I have a client who we are moving VMware ESX from a Data Centre to the head office. They have FGT's at both ends. Soon to be v7

 

And we have about 2 VLAN's at the DC we wish to have replicated over to the head office. 

Head Office: 192.168.2.0/24

Data Centre: 192.168.100.0/24 (Default VLAN)

Data Centre: 192.168.101.0/24 (VLAN 101) - VMware Vmotion

 

The customer already has an existing IPSEC tunnel to the Data Centre from the Head Office and vice versa.

 

If I add the VXLAN as per the cookbook. I am assuming this will break the routing of the existing IPSEC tunnel? I am also assuming that I can run multiple VLAN's over VXLAN? 

 

So should I tell the Head Office Fortigate to route 192.168.100.0/24 & 192.168.101.0/24 to the local VXLAN interfaces? and remove the configuration for the existing IPSEC tunnels?  

 

And when I get this setup, do I just leave the default gateway at the same at both sites? And when a device wants internet access from Head Office on the VXLAN, does it route it over the IPSEC to go out the default gateway at the DC? 

 

I am trying to avoid any potential snags, before deployment. So if anyone has advice/experience that may help. I would be happy to hear it. 

 

Andy

0 REPLIES 0
Labels
Top Kudoed Authors