Fortinet black logo

Introduction

7.2.2
Copy Link
Copy Doc ID d3305d0f-53f4-11ed-9d74-fa163e15d75b:979742
Download PDF

Introduction

Executive summary

Virtual eXtensible LAN (VXLAN) can be used to create a layer-2 overlay network when managing FortiSwitch units over a layer-3 network. The FortiGate device can use the VXLAN to manage multiple FortiSwitch units. If the FortiSwitch unit being managed supports hardware-based VXLAN, the FortiSwitch unit can also forward FortiSwitch VLANs (user traffic) to a FortiGate device over VXLAN. This document is focused on FortiSwitch models that support hardware-based VXLAN.

Intended audience

This guide is intended for an audience who is interested in deploying Fortinet’s Secure Access Solution in a new environment or replacing their equipment in an existing environment. Readers are expected to have a firm understanding of networking, wireless, and security concepts. Interested audiences might include the following:

  • Network, wireless, and security architects

  • Network, wireless, and security engineers

About this guide

The deployment guide provides the design and deployment steps involved in deploying a specific architecture. Readers should first evaluate their environment to determine whether the architecture and design outlined in this guide is suitable for them. It is advisable to review the administration guide if readers are still in the process of selecting the right architecture.

This deployment guide presents one of many possible ways to deploy the solution. It might omit specific steps where readers must make design decisions to further configure their devices. It is recommended that readers also review supplementary material found in the product administration guides, Knowledge Base articles, cookbooks, release notes, and other documents where appropriate.

Introduction

Executive summary

Virtual eXtensible LAN (VXLAN) can be used to create a layer-2 overlay network when managing FortiSwitch units over a layer-3 network. The FortiGate device can use the VXLAN to manage multiple FortiSwitch units. If the FortiSwitch unit being managed supports hardware-based VXLAN, the FortiSwitch unit can also forward FortiSwitch VLANs (user traffic) to a FortiGate device over VXLAN. This document is focused on FortiSwitch models that support hardware-based VXLAN.

Intended audience

This guide is intended for an audience who is interested in deploying Fortinet’s Secure Access Solution in a new environment or replacing their equipment in an existing environment. Readers are expected to have a firm understanding of networking, wireless, and security concepts. Interested audiences might include the following:

  • Network, wireless, and security architects

  • Network, wireless, and security engineers

About this guide

The deployment guide provides the design and deployment steps involved in deploying a specific architecture. Readers should first evaluate their environment to determine whether the architecture and design outlined in this guide is suitable for them. It is advisable to review the administration guide if readers are still in the process of selecting the right architecture.

This deployment guide presents one of many possible ways to deploy the solution. It might omit specific steps where readers must make design decisions to further configure their devices. It is recommended that readers also review supplementary material found in the product administration guides, Knowledge Base articles, cookbooks, release notes, and other documents where appropriate.