Fortinet white logo
Fortinet white logo

Administration Guide

Configuring dynamic firewall addresses for fabric connectors

Configuring dynamic firewall addresses for fabric connectors

You can create dynamic firewall objects that can be dynamically populated when FortiGate communicates with the SDN platform.

To configure dynamic firewall addresses using SDN connectors:
  1. Go to Policy & Objects > Firewall Objects.
  2. In the content pane, click Create New and select Address.
  3. Configure the firewall address settings for your chosen fabric connector:

    Category

    Select Address.

    Name

    Type a name for the firewall address object.

    Type

    Select Dynamic.

    Sub Type

    Select Fabric Connector Address.

    SDN Connector

    Select the fabric connector.

  4. Configure the remaining settings as needed, and click OK.
To configure dynamic IPv6 firewall addresses using SDN connectors:
  1. Go to Policy & Objects > Firewall Objects.
  2. In the content pane, click Create New and select Address.
  3. Configure the IPv6 firewall address settings for your chosen fabric connector:
  4. Category Select IPv6 Address.

    Name

    Type a name for the firewall address object.

    Type Select IPv6 Fabric Connector Address.
    SDN Select a fabric connector that supports IPv6 addresses. For example, Cisco ACI.
  5. Configure the remaining settings as required, and click OK.

Configuring dynamic firewall addresses for fabric connectors

Configuring dynamic firewall addresses for fabric connectors

You can create dynamic firewall objects that can be dynamically populated when FortiGate communicates with the SDN platform.

To configure dynamic firewall addresses using SDN connectors:
  1. Go to Policy & Objects > Firewall Objects.
  2. In the content pane, click Create New and select Address.
  3. Configure the firewall address settings for your chosen fabric connector:

    Category

    Select Address.

    Name

    Type a name for the firewall address object.

    Type

    Select Dynamic.

    Sub Type

    Select Fabric Connector Address.

    SDN Connector

    Select the fabric connector.

  4. Configure the remaining settings as needed, and click OK.
To configure dynamic IPv6 firewall addresses using SDN connectors:
  1. Go to Policy & Objects > Firewall Objects.
  2. In the content pane, click Create New and select Address.
  3. Configure the IPv6 firewall address settings for your chosen fabric connector:
  4. Category Select IPv6 Address.

    Name

    Type a name for the firewall address object.

    Type Select IPv6 Fabric Connector Address.
    SDN Select a fabric connector that supports IPv6 addresses. For example, Cisco ACI.
  5. Configure the remaining settings as required, and click OK.