Before deploying the Azure Resource Manager (ARM) template, complete the following prerequisites:
- Log in to your Azure account.
- Create a service principal. Note the following items as you need them to deploy the Function App:
Relevant FortiOS parameter
You can find this item in Azure Active Directory > Properties > Directory ID. A hybrid licensing deployment does not require this item.
You can find this item in Azure Active Directory > App registrations > (your app).
Service Principal App ID. This is the Application ID for the Registered app used as the Function App API request service principal.
Only appears once. You cannot retrieve the application secret.
Service Principal App Secret. This is the password (Authentication key) for the Registered app used as the Function App API request service principal.
Obtain the following details about the vWAN service:
- vWAN name
- Resource group name
The Remote_sites.txt file serves as the input for Azure functions. The file contains information about all sites that want to connect to vWAN. You will store the file in a storage blob. You must include the following information in the file:
- Site name (Azure uses this as an identifier)
- FortiGate public IP address
- Internal networks behind the FortiGate that need access to the vWAN
- BGP ASN and peering IP address to use
- Login credentials
The following is an example of the content of a Remote_Sites.txt file:
1) Tempe 188.8.131.52 10.0.11.0/24,10.0.15.0/24 azureadmin Password!234 root 169.254.24.24 7224
2) Folsom 184.108.40.206 172.31.1.0/24 azureadmin Password!234 root 169.254.24.25 7225