VXLAN over IPSEC between a Fortigate 40F and a 4011

Hi Community,

I tried in my lab for the moment to use VXLAN over IPSEC between a 4011 and a Fortigate 40F.
This is the result:

  1. Without IPSEC, VXLAN works > I enabled a DHCP server on the Mikrotik and plug a laptop on the Fortigate and it takes an IP
  2. IPSEC between the 4011 and the Fortigate works
  3. VXLAN+IPSEC doesn’t work

About Fortinet, there are two differents configurations who are available,
-one with a VXLAN encryption in the phase 1 of IPSEC tunnel https://community.fortinet.com/t5/FortiGate/Technical-Tip-Basic-VXLAN-over-IPsec-configuration/ta-p/191207 ( I think is not compatible with Mikrotik)

I tried the both for the same result.

My first question is, someone has already use this type of configuration ? is it possible or compatible ?
If yes I will share the Mikrotik’s and Fortigate’s configuration. Maybe one of you will see my mistake

Thank you for your help

Send nudes …ahm config

Fortinet builds vxlan tunnel for fex in lan mode . There are some config examples for that . Maybe you can check those … there is an isec tunnel established with an IP address on tunnel interface on each side. Vxlan endpoint ist than mapped to these interfaces’ IP addresses

Cheers

can you pls show me your configuration without IPSEc? I’ve tried but not working yet.