Fortinet black logo

AWS Administration Guide

Subscribing to the FortiGate

Copy Link
Copy Doc ID f4e6f33e-6876-11ea-9384-00505692583a:764350
Download PDF

Subscribing to the FortiGate

To subscribe to the FortiGate:
  1. Go to the AWS Marketplace’s page for Fortinet FortiGate-VM (BYOL) or FortiGate-VM (on-demand). Select Continue.
  2. Select Manual Launch.
  3. Select Launch with EC2 Console beside the region you want to launch.
  4. Select an instance type, then select Next: Configure Instance Details.
  5. Configure instance details:
    1. In the Network field, select the VPC that you created.
    2. In the Subnet field, select the public subnet.
    3. In the Network interfaces section, you will see the entry for eth0 that was created for the public subnet. Select Add Device to add another network interface (in this example, eth1), and select the private subnet. It is recommended that you assign static IP addresses.
    4. When you have two network interfaces, an EIP is not assigned automatically. You must manually assign one later. Select Review and Launch, then select Launch.
  6. Select an existing key pair or create a new key pair. Select the acknowledgment checkbox. Select Launch Instances.
  7. To easily identify the instance, set a name for it in the Name field.
  8. Since FortiOS 6.2.2, on-demand FortiGate-VMs require connectivity to FortiCare to obtain a valid license. Without connectivity to FortiCare, the FortiGate-VM shuts down for self-protection. Ensure the following:
    1. Outgoing connectivity to https://directregistration.fortinet.com:443 is allowed in security groups and ACLs.
    2. You have assigned a public IP address (default or EIP). If you have not enabled a public address during instance creation, follow the remaining steps to assign an EIP and bring up the FortiGate-VM again.
  9. Configure an EIP:
    1. In the Network & Security menu, select Elastic IPs, then select one that is available for you to use or create one. Select Actions > Associate Address. If you do not have one available to use, create one.

    2. In the Resource type section, select Network Interface.
    3. In the Network interface field, select the interface ID of the network interface that you created for the public subnet (in this example, eth0). In the Private IP field, select the IP address that belongs to the public subnet. To find these values, go to the EC2 Management Console, select Instances, and select the interface in the Network interfaces section in the lower pane of the page (Interface ID and Private IP Address fields). Select Associate. A message is displayed indicating the address association was successful. Note that if the Internet Gateway isn’t associated with a VPC, the elastic IP assignment will fail.

Subscribing to the FortiGate

To subscribe to the FortiGate:
  1. Go to the AWS Marketplace’s page for Fortinet FortiGate-VM (BYOL) or FortiGate-VM (on-demand). Select Continue.
  2. Select Manual Launch.
  3. Select Launch with EC2 Console beside the region you want to launch.
  4. Select an instance type, then select Next: Configure Instance Details.
  5. Configure instance details:
    1. In the Network field, select the VPC that you created.
    2. In the Subnet field, select the public subnet.
    3. In the Network interfaces section, you will see the entry for eth0 that was created for the public subnet. Select Add Device to add another network interface (in this example, eth1), and select the private subnet. It is recommended that you assign static IP addresses.
    4. When you have two network interfaces, an EIP is not assigned automatically. You must manually assign one later. Select Review and Launch, then select Launch.
  6. Select an existing key pair or create a new key pair. Select the acknowledgment checkbox. Select Launch Instances.
  7. To easily identify the instance, set a name for it in the Name field.
  8. Since FortiOS 6.2.2, on-demand FortiGate-VMs require connectivity to FortiCare to obtain a valid license. Without connectivity to FortiCare, the FortiGate-VM shuts down for self-protection. Ensure the following:
    1. Outgoing connectivity to https://directregistration.fortinet.com:443 is allowed in security groups and ACLs.
    2. You have assigned a public IP address (default or EIP). If you have not enabled a public address during instance creation, follow the remaining steps to assign an EIP and bring up the FortiGate-VM again.
  9. Configure an EIP:
    1. In the Network & Security menu, select Elastic IPs, then select one that is available for you to use or create one. Select Actions > Associate Address. If you do not have one available to use, create one.

    2. In the Resource type section, select Network Interface.
    3. In the Network interface field, select the interface ID of the network interface that you created for the public subnet (in this example, eth0). In the Private IP field, select the IP address that belongs to the public subnet. To find these values, go to the EC2 Management Console, select Instances, and select the interface in the Network interfaces section in the lower pane of the page (Interface ID and Private IP Address fields). Select Associate. A message is displayed indicating the address association was successful. Note that if the Internet Gateway isn’t associated with a VPC, the elastic IP assignment will fail.