<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: FIGW - IPSEC + VXLAN + FRAGMENTATION AND REASSEMBLY over L2 link in ExtremeSwitching (VSP/Fabric Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/figw-ipsec-vxlan-fragmentation-and-reassembly-over-l2-link/m-p/8912#M493</link>
    <description>EF,&lt;BR /&gt;&lt;BR /&gt;IPSEC is always over L3. MACSEC is over L2.&lt;BR /&gt;Here a possible setup&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="bcc6d49f81314676b3ada78d661674f7.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/4034iB747BEE0B2143D54/image-size/large?v=v2&amp;amp;px=999" role="button" title="bcc6d49f81314676b3ada78d661674f7.png" alt="bcc6d49f81314676b3ada78d661674f7.png" /&gt;&lt;/span&gt;Mig</description>
    <pubDate>Fri, 26 Nov 2021 13:23:00 GMT</pubDate>
    <dc:creator>Miguel-Angel_RO</dc:creator>
    <dc:date>2021-11-26T13:23:00Z</dc:date>
    <item>
      <title>FIGW - IPSEC + VXLAN + FRAGMENTATION AND REASSEMBLY over L2 link</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/figw-ipsec-vxlan-fragmentation-and-reassembly-over-l2-link/m-p/8909#M490</link>
      <description>Hi team,&lt;BR /&gt;&lt;BR /&gt;In a L2 connection through ISP with MTU less of 1600bytes, I´m using FIGWs for fabric extend (VXLAN) and fragmentation &amp;amp; reassembly to establish isis adjacencies&amp;nbsp; without problem.&lt;BR /&gt;&lt;BR /&gt;Now I want to add IPSEC but I review all the topologies avalaible for IPSEC and all of them are trought L3, the question is, in a link L2 is IPSEC topology supported? &lt;BR /&gt;&lt;BR /&gt;Regards&lt;BR /&gt;&lt;BR /&gt;EF</description>
      <pubDate>Mon, 22 Nov 2021 11:20:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/figw-ipsec-vxlan-fragmentation-and-reassembly-over-l2-link/m-p/8909#M490</guid>
      <dc:creator>EF</dc:creator>
      <dc:date>2021-11-22T11:20:00Z</dc:date>
    </item>
    <item>
      <title>RE: FIGW - IPSEC + VXLAN + FRAGMENTATION AND REASSEMBLY over L2 link</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/figw-ipsec-vxlan-fragmentation-and-reassembly-over-l2-link/m-p/8910#M491</link>
      <description>EF,&lt;BR /&gt;You should describe deeper your setup.&lt;BR /&gt;The IPSec tunnel+frag/defrag can be performed at the FIGW level while the isis logical interface is done at the switch level.&lt;BR /&gt;You should describe what you have today in a picture to be able to guide you.&lt;BR /&gt;&lt;BR /&gt;Mig</description>
      <pubDate>Thu, 25 Nov 2021 11:49:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/figw-ipsec-vxlan-fragmentation-and-reassembly-over-l2-link/m-p/8910#M491</guid>
      <dc:creator>Miguel-Angel_RO</dc:creator>
      <dc:date>2021-11-25T11:49:00Z</dc:date>
    </item>
    <item>
      <title>RE: FIGW - IPSEC + VXLAN + FRAGMENTATION AND REASSEMBLY over L2 link</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/figw-ipsec-vxlan-fragmentation-and-reassembly-over-l2-link/m-p/8911#M492</link>
      <description>&lt;P&gt;I´ll try better, this is my working environment (VXLAN+FRAGMENTATION) , My deploy is L2 link&amp;nbsp; with MTU less 1600 bytes between two FIGWs and it´s working fine:&lt;/P&gt;
&lt;DIV class="media" style="overflow: hidden; zoom: 1;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="qbEc5y6HT0m0LOXaCzIQ_l2.jpeg"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/3377i432F08CD9FDA22F8/image-size/large?v=v2&amp;amp;px=999" role="button" title="qbEc5y6HT0m0LOXaCzIQ_l2.jpeg" alt="qbEc5y6HT0m0LOXaCzIQ_l2.jpeg" /&gt;&lt;/span&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now I want to add IPSEC but I'm unable to add the necessary commands because there are exclusion with this config.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After my investigation I see that all topologies with IPSEC are over L3 networks,&lt;/P&gt;
&lt;DIV class="media" style="overflow: hidden; zoom: 1;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="mDwTUfSyRXixo0QmODVc_l3.jpeg"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/3309iE7E785CD4D5C4F9C/image-size/large?v=v2&amp;amp;px=999" role="button" title="mDwTUfSyRXixo0QmODVc_l3.jpeg" alt="mDwTUfSyRXixo0QmODVc_l3.jpeg" /&gt;&lt;/span&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so I begin to suspect that it´s not supported over L2 links.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It´s a question about topologies supported with FIGW and IPSEC.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;EF&lt;/P&gt;</description>
      <pubDate>Thu, 25 Nov 2021 16:47:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/figw-ipsec-vxlan-fragmentation-and-reassembly-over-l2-link/m-p/8911#M492</guid>
      <dc:creator>EF</dc:creator>
      <dc:date>2021-11-25T16:47:00Z</dc:date>
    </item>
    <item>
      <title>RE: FIGW - IPSEC + VXLAN + FRAGMENTATION AND REASSEMBLY over L2 link</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/figw-ipsec-vxlan-fragmentation-and-reassembly-over-l2-link/m-p/8912#M493</link>
      <description>EF,&lt;BR /&gt;&lt;BR /&gt;IPSEC is always over L3. MACSEC is over L2.&lt;BR /&gt;Here a possible setup&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="bcc6d49f81314676b3ada78d661674f7.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/4034iB747BEE0B2143D54/image-size/large?v=v2&amp;amp;px=999" role="button" title="bcc6d49f81314676b3ada78d661674f7.png" alt="bcc6d49f81314676b3ada78d661674f7.png" /&gt;&lt;/span&gt;Mig</description>
      <pubDate>Fri, 26 Nov 2021 13:23:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/figw-ipsec-vxlan-fragmentation-and-reassembly-over-l2-link/m-p/8912#M493</guid>
      <dc:creator>Miguel-Angel_RO</dc:creator>
      <dc:date>2021-11-26T13:23:00Z</dc:date>
    </item>
    <item>
      <title>RE: FIGW - IPSEC + VXLAN + FRAGMENTATION AND REASSEMBLY over L2 link</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/figw-ipsec-vxlan-fragmentation-and-reassembly-over-l2-link/m-p/8913#M494</link>
      <description>Running IPsec tunnels over a L2 WAN (e.g. VPLS) should be possible, but i have never tried it. You would not set any wan-intf-gw-ip on the FIGW.&lt;BR /&gt;The FIGW would thus ARP for the remote end-points.</description>
      <pubDate>Mon, 29 Nov 2021 17:48:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/figw-ipsec-vxlan-fragmentation-and-reassembly-over-l2-link/m-p/8913#M494</guid>
      <dc:creator>Ludovico_Steven</dc:creator>
      <dc:date>2021-11-29T17:48:00Z</dc:date>
    </item>
    <item>
      <title>RE: FIGW - IPSEC + VXLAN + FRAGMENTATION AND REASSEMBLY over L2 link</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/figw-ipsec-vxlan-fragmentation-and-reassembly-over-l2-link/m-p/8914#M495</link>
      <description>Hi Ludovico,&lt;BR /&gt;&lt;BR /&gt;this is the problem, if I´m not wrong,&amp;nbsp; that "set global wan-intf-gw-ip&amp;nbsp; " is mandatory for IPSEC config, but in a l2 connection I dont have it.&lt;BR /&gt;&lt;BR /&gt;Regards&lt;BR /&gt;&lt;BR /&gt;EF</description>
      <pubDate>Mon, 29 Nov 2021 17:57:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/figw-ipsec-vxlan-fragmentation-and-reassembly-over-l2-link/m-p/8914#M495</guid>
      <dc:creator>EF</dc:creator>
      <dc:date>2021-11-29T17:57:00Z</dc:date>
    </item>
  </channel>
</rss>

