Configuring dynamic firewall addresses for fabric connectors
You can create dynamic firewall objects that can be dynamically populated when FortiGate communicates with the SDN platform.
To configure dynamic firewall addresses using SDN connectors:
- Go to Policy & Objects > Firewall Objects.
- In the content pane, click Create New and select Address.
- Configure the firewall address settings for your chosen fabric connector:
Category
Select Address.
Name
Type a name for the firewall address object.
Type
Select Dynamic.
Sub Type
Select Fabric Connector Address.
SDN Connector
Select the fabric connector.
- Configure the remaining settings as needed, and click OK.
To configure dynamic IPv6 firewall addresses using SDN connectors:
- Go to Policy & Objects > Firewall Objects.
- In the content pane, click Create New and select Address.
- Configure the IPv6 firewall address settings for your chosen fabric connector:
- Configure the remaining settings as required, and click OK.
Category | Select IPv6 Address. |
Name |
Type a name for the firewall address object. |
Type | Select IPv6 Fabric Connector Address. |
SDN | Select a fabric connector that supports IPv6 addresses. For example, Cisco ACI. |