Deploying the FortiGate-VM
Deploying the FortiGate-VM
- Set up the OCI VCN environment. See Creating a VCN for same-AD HA topology.
- Deploy FortiGate-VMs in the environment for an active-passive configuration. See Creating a FortiGate-VM instance. To deploy FortiGate-VM from the marketplace, see Deploying FortiGate-VM via the marketplace.
- Configure extra VNICs for the FortiGate-VM. You must ensure there are at least four network interfaces configured for each instance. See Checking the prerequisites. To create an extra VNIC, see Creating the second virtual network interface (VNIC). To configure the extra VNIC, see Configuring the second VNIC on the FortiGate-VM.
- Update route rules to point to the internal/trust private IP address on the active FortiGate. It is recommended to create a separate route table for the internal/trust subnet:
- Go to Networking > Virtual Cloud Networks > <VCN used> > Route Tables, then click Create Route Table.
- Specify the route table to point to the internal/trust private IP address on the active FortiGate:
- Go to Networking > Virtual Cloud Networks > <VCN used>. Edit the desired subnet.
- Under Route Table, update the configuration to the newly created route table.
Deploying the FortiGate-VM
Deploying the FortiGate-VM
- Set up the OCI VCN environment. See Creating a VCN for same-AD HA topology.
- Deploy FortiGate-VMs in the environment for an active-passive configuration. See Creating a FortiGate-VM instance. To deploy FortiGate-VM from the marketplace, see Deploying FortiGate-VM via the marketplace.
- Configure extra VNICs for the FortiGate-VM. You must ensure there are at least four network interfaces configured for each instance. See Checking the prerequisites. To create an extra VNIC, see Creating the second virtual network interface (VNIC). To configure the extra VNIC, see Configuring the second VNIC on the FortiGate-VM.
- Update route rules to point to the internal/trust private IP address on the active FortiGate. It is recommended to create a separate route table for the internal/trust subnet:
- Go to Networking > Virtual Cloud Networks > <VCN used> > Route Tables, then click Create Route Table.
- Specify the route table to point to the internal/trust private IP address on the active FortiGate:
- Go to Networking > Virtual Cloud Networks > <VCN used>. Edit the desired subnet.
- Under Route Table, update the configuration to the newly created route table.