- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi all,
anyone has experience/quick guide with implementation of VXLAN over IPSEC?
I'm trying to set it up with a Fortinet firewall and no success.
Tried to follow this guide https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut... + VPN with empty group.
I correctly see phase 1 UP and phase 2 UP with same subnet for MyTS and PeerTS, so the IPSEC part seems to be ok.
Thank you
Hey Guys,
thank you for your feedback.
I just solved, the missing key point was related to VTI; once created on fortinet side (https://community.fortinet.com/t5/FortiGate/Technical-Tip-VXLAN-over-IPsec-for-multiple-VLANs-using-...I created it also on Check Point side and VXLAN started to work properly.
It is important to remember:
- allow traffic from peer's VTI to the Check Point GW on port 4789.
- Add to the bridge the VXLAN interface and a VLAN interface, not a normal interface (eth1.10 is good, eth1 is not)
- configure L3 for that VLAN on a port outside the bridge.
Hope to help someone in the future 🙂
Did you attempt to troubleshoot the VXLAN portion of this?
The SK you linked should provide some troubleshooting steps.
You might also check with fw monitor/tcpdump to see if the traffic is appearing on the correct interfaces.
I did VxLan with OPNSense across IPSEC. Did you look for UDP/4789 packets traversing the IPSEC tunnel?
Hey Guys,
thank you for your feedback.
I just solved, the missing key point was related to VTI; once created on fortinet side (https://community.fortinet.com/t5/FortiGate/Technical-Tip-VXLAN-over-IPsec-for-multiple-VLANs-using-...I created it also on Check Point side and VXLAN started to work properly.
It is important to remember:
- allow traffic from peer's VTI to the Check Point GW on port 4789.
- Add to the bridge the VXLAN interface and a VLAN interface, not a normal interface (eth1.10 is good, eth1 is not)
- configure L3 for that VLAN on a port outside the bridge.
Hope to help someone in the future 🙂
Hi did you configured a Layer 2 VXLAN or a Layer 3 VXLAN tunnel?
I have configured a Layer 2 VXLAN tunnel which is working but I want to encrypt it using IPSEC.
I stuck and don't know what to do? Can you give me some insight, thx.
Hey
VXLAN is a technolgy to allow layer 2 connectivity thanks to layer3, so i cannot understand your first question
Anyway, follow this sk https://support.checkpoint.com/results/sk/sk170014 and what i wrote in the old post
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 20 | |
| 19 | |
| 19 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY