<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VXLAN over IPSEC configuration in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VXLAN-over-IPSEC-configuration/m-p/159613#M27987</link>
    <description>&lt;P&gt;Hey Guys,&lt;/P&gt;&lt;P&gt;thank you for your feedback.&lt;/P&gt;&lt;P&gt;I just solved, the missing key point was related to VTI; once created on fortinet side (&lt;A href="https://community.fortinet.com/t5/FortiGate/Technical-Tip-VXLAN-over-IPsec-for-multiple-VLANs-using-software/ta-p/195488)" target="_blank" rel="noopener"&gt;https://community.fortinet.com/t5/FortiGate/Technical-Tip-VXLAN-over-IPsec-for-multiple-VLANs-using-software/ta-p/195488)&amp;nbsp;&amp;nbsp;&lt;/A&gt;I created it also on Check Point side and VXLAN started to work properly.&lt;/P&gt;&lt;P&gt;It is important to remember:&lt;/P&gt;&lt;P&gt;- allow traffic from peer's VTI to the Check Point GW on port&amp;nbsp;&lt;SPAN&gt;4789.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- Add to the bridge the VXLAN interface and a&amp;nbsp;&lt;STRONG&gt;VLAN interface&lt;/STRONG&gt;, not a normal interface (eth1.10 is good, eth1 is not)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- configure L3 for that VLAN on a port &lt;/SPAN&gt;&lt;STRONG&gt;outside &lt;/STRONG&gt;&lt;SPAN&gt;the bridge.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope to help someone in the future &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 14 Oct 2022 19:54:53 GMT</pubDate>
    <dc:creator>CheckPointerXL</dc:creator>
    <dc:date>2022-10-14T19:54:53Z</dc:date>
    <item>
      <title>VXLAN over IPSEC configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VXLAN-over-IPSEC-configuration/m-p/159447#M27909</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;anyone has experience/quick guide with implementation of VXLAN over IPSEC?&lt;/P&gt;&lt;P&gt;I'm trying to set it up with a Fortinet firewall and no success.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tried to follow this guide &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk170014" target="_blank" rel="noopener"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk170014&lt;/A&gt;&amp;nbsp;+ VPN with empty group.&lt;/P&gt;&lt;P&gt;I correctly see phase 1 UP and phase 2 UP with same subnet for MyTS and PeerTS, so the IPSEC part seems to be ok.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 13 Oct 2022 14:10:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VXLAN-over-IPSEC-configuration/m-p/159447#M27909</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2022-10-13T14:10:26Z</dc:date>
    </item>
    <item>
      <title>Re: VXLAN over IPSEC configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VXLAN-over-IPSEC-configuration/m-p/159486#M27920</link>
      <description>&lt;P&gt;Did you attempt to troubleshoot the VXLAN portion of this?&lt;BR /&gt;The SK you linked should provide some troubleshooting steps.&lt;BR /&gt;You might also check with fw monitor/tcpdump to see if the traffic is appearing on the correct interfaces.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2022 20:11:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VXLAN-over-IPSEC-configuration/m-p/159486#M27920</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-10-13T20:11:31Z</dc:date>
    </item>
    <item>
      <title>Re: VXLAN over IPSEC configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VXLAN-over-IPSEC-configuration/m-p/159591#M27973</link>
      <description>&lt;P&gt;I did VxLan with OPNSense across IPSEC. Did you look for UDP/4789 packets traversing the IPSEC tunnel?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 16:44:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VXLAN-over-IPSEC-configuration/m-p/159591#M27973</guid>
      <dc:creator>dphonovation</dc:creator>
      <dc:date>2022-10-14T16:44:08Z</dc:date>
    </item>
    <item>
      <title>Re: VXLAN over IPSEC configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VXLAN-over-IPSEC-configuration/m-p/159613#M27987</link>
      <description>&lt;P&gt;Hey Guys,&lt;/P&gt;&lt;P&gt;thank you for your feedback.&lt;/P&gt;&lt;P&gt;I just solved, the missing key point was related to VTI; once created on fortinet side (&lt;A href="https://community.fortinet.com/t5/FortiGate/Technical-Tip-VXLAN-over-IPsec-for-multiple-VLANs-using-software/ta-p/195488)" target="_blank" rel="noopener"&gt;https://community.fortinet.com/t5/FortiGate/Technical-Tip-VXLAN-over-IPsec-for-multiple-VLANs-using-software/ta-p/195488)&amp;nbsp;&amp;nbsp;&lt;/A&gt;I created it also on Check Point side and VXLAN started to work properly.&lt;/P&gt;&lt;P&gt;It is important to remember:&lt;/P&gt;&lt;P&gt;- allow traffic from peer's VTI to the Check Point GW on port&amp;nbsp;&lt;SPAN&gt;4789.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- Add to the bridge the VXLAN interface and a&amp;nbsp;&lt;STRONG&gt;VLAN interface&lt;/STRONG&gt;, not a normal interface (eth1.10 is good, eth1 is not)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- configure L3 for that VLAN on a port &lt;/SPAN&gt;&lt;STRONG&gt;outside &lt;/STRONG&gt;&lt;SPAN&gt;the bridge.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope to help someone in the future &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 19:54:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VXLAN-over-IPSEC-configuration/m-p/159613#M27987</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2022-10-14T19:54:53Z</dc:date>
    </item>
    <item>
      <title>Re: VXLAN over IPSEC configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VXLAN-over-IPSEC-configuration/m-p/189779#M34967</link>
      <description>&lt;P&gt;Hi did you configured a Layer 2 VXLAN or a Layer 3 VXLAN tunnel?&lt;/P&gt;&lt;P&gt;I have configured a Layer 2 VXLAN tunnel which is working but I want to encrypt it using IPSEC.&lt;/P&gt;&lt;P&gt;I stuck and don't know what to do? Can you give me some insight, thx.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Aug 2023 14:01:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VXLAN-over-IPSEC-configuration/m-p/189779#M34967</guid>
      <dc:creator>uwillems</dc:creator>
      <dc:date>2023-08-17T14:01:05Z</dc:date>
    </item>
    <item>
      <title>Re: VXLAN over IPSEC configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VXLAN-over-IPSEC-configuration/m-p/189782#M34968</link>
      <description>&lt;P&gt;Hey&lt;/P&gt;
&lt;P&gt;VXLAN is a technolgy to allow layer 2 connectivity thanks to layer3, so i cannot understand your first question&lt;/P&gt;
&lt;P&gt;Anyway, follow this sk&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk170014" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk170014&lt;/A&gt; and what i wrote in the old post&lt;/P&gt;</description>
      <pubDate>Thu, 17 Aug 2023 14:25:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VXLAN-over-IPSEC-configuration/m-p/189782#M34968</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2023-08-17T14:25:40Z</dc:date>
    </item>
  </channel>
</rss>

