<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>L2 &#8211; 21點情報網</title>
	<atom:link href="https://ailog.tw/lifelog/tag/l2/feed/" rel="self" type="application/rss+xml" />
	<link>https://ailog.tw/lifelog</link>
	<description></description>
	<lastBuildDate>Thu, 25 Nov 2021 04:16:07 +0000</lastBuildDate>
	<language>zh-TW</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.3</generator>
	<item>
		<title>透過Fortigate VPN建立VXLAN讓分隔異地的兩端使用相同的區域網路</title>
		<link>https://ailog.tw/lifelog/2021/10/31/fortigate-vxlan/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Sun, 31 Oct 2021 09:39:09 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[fortigate]]></category>
		<category><![CDATA[L2]]></category>
		<category><![CDATA[VPN]]></category>
		<category><![CDATA[VXLAN]]></category>
		<category><![CDATA[專線]]></category>
		<category><![CDATA[相同網段]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=11473</guid>

					<description><![CDATA[人生真的是充滿了挑戰，小編最近處理了一個透過Fortigate建立VXLAN讓分隔兩地的網路可以串連在一起，並 &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2021/10/31/fortigate-vxlan/" class="more-link">閱讀全文<span class="screen-reader-text">〈透過Fortigate VPN建立VXLAN讓分隔異地的兩端使用相同的區域網路〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p><span style="font-size: 14pt; font-family: verdana, geneva;">人生真的是充滿了挑戰，小編最近處理了一個透過Fortigate建立VXLAN讓分隔兩地的網路可以串連在一起，並且形成同一個內部網路，效果就跟點對點(point to point network)L2專線一樣，雖然反應速度略遜專線，但價格差距可是相當驚人，因此就可以了解為何會有企業想這樣做了吧!<span id="more-11473"></span></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">一、情境說明</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">(1)、IDC及DR兩端各有一台Fortigate防火牆，設備韌體均採用6.4.4(1803)，希望透過VPN VXLAN技術，讓分隔兩端的網路形成一個虛擬的L2內網。</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">(2)、情境架構圖：<br />
<img fetchpriority="high" decoding="async" class="alignnone wp-image-11479 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/10/fortigate-vxlan-00.jpg" alt="" width="836" height="699" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/10/fortigate-vxlan-00.jpg 836w, https://ailog.tw/lifelog/wp-content/uploads/2021/10/fortigate-vxlan-00-300x251.jpg 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/10/fortigate-vxlan-00-768x642.jpg 768w" sizes="(max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /><br />
</span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">(3)、本範例設定過程均採用Conosle模式<br />
(4)、VXLAN<span style="font-weight: 400;">該功能只支援FortOS 5.4版本以上，但5.6以上功能較為完善。<br />
(5)、該功能是透過IPSec VPN架構進行，但無法透過加速晶片進行加速，因此如果流量過大，請注意設備等級及效能。<br />
(6)、本範例防火牆相關資訊<br />
Wan interface：wan1<br />
Lan interface：internal1<br />
IDC防火牆Wan端真實IP：192.192.205.1<br />
DR防火牆Wan端真實IP：192.192.209.1<br />
VPN psksecret：0800080080</span></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;"><span style="font-weight: 400;"><br />
</span>二、設定步驟<br />
(1)、IDC端的Fortigate設定WAN端IP及預設閘道<br />
指令：</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">config system interface</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">edit &#8220;wan1&#8221;</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set vdom &#8220;root&#8221;</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set ip <span style="color: #ff0000;">192.192.205.1 255.255.255.0</span></span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set allowaccess ping</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set type physical</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set role wan</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set snmp-index 1</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">next<br />
end</span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">config router static</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">edit 1</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set gateway <span style="color: #ff0000;">192.192.205.254</span></span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set device &#8220;wan1&#8221;</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">next</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">end</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">(2)、DR端的Fortigate設定WAN端IP及預設閘道<br />
指令：<br />
config system interface<br />
edit &#8220;wan1&#8221;<br />
set vdom &#8220;root&#8221;<br />
set ip <span style="color: #ff0000;">192.192.209.1 255.255.255.0</span><br />
set allowaccess ping<br />
set type physical<br />
set role wan<br />
set snmp-index 1<br />
next<br />
end</span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">config router static</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">edit 1</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set gateway <span style="color: #ff0000;">192.192.209.254</span></span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set device &#8220;wan1&#8221;</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">next</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">end</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">(3)、IDC端的Fortigate建立VXLAN VPN<br />
指令：<br />
config vpn ipsec phase1-interface</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">edit VXLAN</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">set interface wan1</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">set peertype any</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">set proposal aes256-sha1</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">set encapsulation vxlan</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">set encapsulation-address ipv4</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">set encap-local-gw4 <span style="color: #ff0000;">192.192.205.1</span></span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">set encap-remote-gw4 <span style="color: #ff0000;">192.192.209.1</span></span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">set remote-gw <span style="color: #ff0000;">192.192.209.1</span></span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">set psksecret <span style="font-weight: 400; color: #ff0000;">0800080080</span></span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">next</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">end</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">config vpn ipsec phase2-interface</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">edit VXLAN_ph2</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">set phase1name VXLAN</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">set proposal aes256-sha1</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">set auto-negotiate enable</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">next</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">end</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">(4)、DR端的Fortigate建立VXLAN VPN<br />
指令：<br />
config vpn ipsec phase1-interface</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">edit VXLAN</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set interface wan1</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set peertype any</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set proposal aes256-sha1</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set encapsulation vxlan</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set encapsulation-address ipv4</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set encap-local-gw4 <span style="color: #ff0000;">192.192.209.1</span></span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set encap-remote-gw4 <span style="color: #ff0000;">192.192.205.1</span></span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set remote-gw <span style="color: #ff0000;">192.192.205.1</span></span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set psksecret <span style="font-weight: 400; color: #ff0000;">0800080080</span></span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">next</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">end</span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">config vpn ipsec phase2-interface</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">edit VXLAN_ph2</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set phase1name VXLAN</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set proposal aes256-sha1</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set auto-negotiate enable</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">next</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">end</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">(5)、在IDC及DR兩端的Fortigate設定VPN介面採用L2傳遞模式<br />
指令：<br />
config system interface<br />
edit VXLAN<br />
<span style="color: #ff0000;">set l2forward enable<br />
<span style="font-weight: 400;">set mtu-override enable</span></span><br />
next<br />
end<br />
</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">(6)、在IDC及DR兩端的Fortigate建立虛擬Switch<br />
指令：<br />
config system switch-interface<br />
edit VXLAN-SWITCH<br />
set vdom root<br />
set member <span style="color: #ff0000;">internal1 VXLAN</span><br />
next<br />
end<br />
<img decoding="async" class="alignnone wp-image-11480 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/10/fortigate-vxlan-01.jpg" alt="" width="1370" height="103" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/10/fortigate-vxlan-01.jpg 1370w, https://ailog.tw/lifelog/wp-content/uploads/2021/10/fortigate-vxlan-01-300x23.jpg 300w, https://ailog.tw/lifelog/wp-content/uploads/2021/10/fortigate-vxlan-01-1024x77.jpg 1024w, https://ailog.tw/lifelog/wp-content/uploads/2021/10/fortigate-vxlan-01-768x58.jpg 768w" sizes="(max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /><br />
備註說明：建立完畢虛擬SWITCH後的網頁畫面</span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">(7)、在IDC及DR兩端的Fortigate設定<br />
config system global<br />
<span style="color: #ff0000;">set honor-df disable</span><br />
end<br />
備註說明：<br />
<span style="font-size: 12pt;">FortiOS does not send back an ICMP “destination unreachable, fragmentation needed and DF set” to the source when an IP packet with the DF bit set and a size greater than the tunnel MTU cannot be forwarded inside the VxLAN-IPsec tunne</span><br />
</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">三、實測<br />
(1)、在IDC端Fortigate防火牆的<span style="color: #ff0000;">internal1<span style="color: #000000;">接上一台電腦，並把IP設定為<span style="color: #ff0000;">192.168.100.1</span>/24。</span></span></span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">(2)、在DR端Fortigate防火牆的<span style="color: #ff0000;">internal1</span>接上一台電腦，並把IP設定為<span style="color: #ff0000;">192.168.100.2</span>/24。</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">(3)<span style="color: #ff0000;"><span style="color: #000000;">、透過這兩台電腦進行IP互ping的動作(記得關閉電腦上的防火牆限制)，如果可以通那就完成所有設定了。</span></span></span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">四、輔助說明</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">設定過程中需要設定<br />
<span style="color: #ff0000;"><span style="font-size: 14pt; font-family: verdana, geneva;">set l2forward enable</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva; color: #000000;">及</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">set honor-df disable<br />
</span><span style="color: #000000;">的參考說明：<br />
<a href="https://community.fortinet.com/t5/FortiGate/Technical-Tip-Global-setting-honor-df-explained/ta-p/197002?externalID=FD51964">https://community.fortinet.com/t5/FortiGate/Technical-Tip-Global-setting-honor-df-explained/ta-p/197002?externalID=FD51964</a></span><br />
</span></span></p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
