‎11-13-2025 11:49 AM
Background: I inherited a network with VOSS fabric at two sites (Site A and Site B) connected via SonicWall site-to-site IPsec VPN. It appears the original engineer's intent was to implement Fabric Extend between sites, but this was never completed. For now, I need basic management visibility to edge switches at the remote site through the existing VPN tunnel. I can work on properly implementing Fabric Extend later.
The Problem:
Environment:
What Works:
What I've Found:
The Question: When traffic from the firewall (VLAN 100) is destined for edge switch CLIP IPs, why is the core responding with the edge switch's IP address but the CORE's MAC address? Is this related to the DORESP setting on VLAN 100?
Has anyone encountered this scenario where fabric management IPs need to be reachable across a site-to-site VPN (without Fabric Extend)? What's the proper configuration to allow the firewall to reach edge switches without the cores proxying the response?
Any guidance would be greatly appreciated!
‎11-27-2025 04:09 AM
Hi Manny,
I have some questions;
Site A and B share the same MGMT Clip IP Subnet or are they different?
Whats the next-hop from Site A to B and from B to A?
Regarding your question, I would guess that you see the core switch mac as src is because the core switch is the next-hop in the route for the response form the edge switch. Does the core and firewall both share an IP Interface in VLAN 100? If so, that would explain why you see the mac of the core for the response.
Best regards,
Philipp