Hi All,
I have a client who we are moving VMware ESX from a Data Centre to the head office. They have FGT's at both ends. Soon to be v7
And we have about 2 VLAN's at the DC we wish to have replicated over to the head office.
Head Office: 192.168.2.0/24
Data Centre: 192.168.100.0/24 (Default VLAN)
Data Centre: 192.168.101.0/24 (VLAN 101) - VMware Vmotion
The customer already has an existing IPSEC tunnel to the Data Centre from the Head Office and vice versa.
If I add the VXLAN as per the cookbook. I am assuming this will break the routing of the existing IPSEC tunnel? I am also assuming that I can run multiple VLAN's over VXLAN?
So should I tell the Head Office Fortigate to route 192.168.100.0/24 & 192.168.101.0/24 to the local VXLAN interfaces? and remove the configuration for the existing IPSEC tunnels?
And when I get this setup, do I just leave the default gateway at the same at both sites? And when a device wants internet access from Head Office on the VXLAN, does it route it over the IPSEC to go out the default gateway at the DC?
I am trying to avoid any potential snags, before deployment. So if anyone has advice/experience that may help. I would be happy to hear it.
Andy
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.