Home
Product Pillars
Network Security
Network Security
FortiGate / FortiOS
FortiGate 5000
FortiGate 6000
FortiGate 7000
FortiProxy
NOC & SOC Management
FortiManager
FortiManager Cloud
FortiAnalyzer
FortiAnalyzer Cloud
FortiMonitor
FortiGate Cloud
Enterprise Networking
Secure SD-WAN
FortiLAN Cloud
FortiSwitch
FortiAP / FortiWiFi
FortiAP-U Series
FortiNAC-F
FortiExtender
FortiExtender Cloud
FortiAIOps
Business Communications
FortiFone
FortiVoice
FortiVoice Cloud
FortiRecorder
FortiCamera
Zero Trust Access
ZTNA
Zero Trust Network Access
FortiClient EMS
SASE
FortiSASE
Identity
FortiAuthenticator
FortiTrust Identity
FortiToken Cloud
FortiToken
Cloud Security
Hybrid Cloud Security
FortiGate Public Cloud
FortiGate Private Cloud
Flex-VM
Cloud Native Protection
FortiCNP
FortiDevSec
Web Application / API Protection
FortiWeb
FortiWeb Cloud
FortiADC
FortiGSLB
SAAS Security
FortiMail
FortiMail Cloud
FortiCASB
Security Operations
SOC Platform
FortiAnalyzer
FortiAnalyzer Cloud
FortiSIEM
/
FortiSIEM Cloud
FortiSOAR
FortiPhish
Advanced Threat Protection
FortiSandbox
FortiSandbox Cloud
FortiNDR
FortiDeceptor
FortiInsight
FortiInsight Cloud
FortiIsolator
Endpoint Security
FortiClient
FortiClient Cloud
FortiEDR
Best Practices
Solution Hubs
Cloud
FortiCloud
Public & Private Cloud
Popular Solutions
Secure SD-WAN
Zero Trust Network Access
Secure Access
Security Fabric
Tele-Working
Multi-Factor Authentication
FortiASIC
Operational Technology
MSSP
4-D Resources
Secure SD-WAN
Zero Trust Network Access
Wireless
Switching
Secure Access Service Edge
Next Generation Firewall
Hardware Guides
FortiAnalyzer
FortiAnalyzer Big-Data
FortiADC
FortiAI
FortiAP / FortiWiFi
FortiAP U-Series
FortiAuthenticator
FortiCache
FortiCarrier
FortiController
FortiDDoS
FortiDDoS-F
FortiDeceptor
FortiEdge
FortiExtender
FortiGate
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiHypervisor
FortiIsolator
FortiMail
FortiManager
FortiNAC
FortiNDR
FortiProxy
FortiRecorder
FortiRPS
FortiSandbox
FortiSIEM
FortiSwitch
FortiTester
FortiToken
FortiVoice
FortiWAN
FortiWeb
FortiWLC
FortiWLM
Product A-Z
AscenLink
AV Engine
AWS Firewall Rules
FortiADC
FortiADC E Series
FortiADC Manager
FortiADC Private Cloud
FortiADC Public Cloud
FortiAIOps
FortiAnalyzer
FortiAnalyzer BigData
FortiAnalyzer BigData Private Cloud
FortiAnalyzer Cloud
FortiAnalyzer Private Cloud
FortiAnalyzer Public Cloud
FortiAP / FortiWiFi
FortiAP-U Series
FortiAuthenticator
FortiAuthenticator Private Cloud
FortiAuthenticator Public Cloud
FortiBalancer
FortiBridge
FortiCache
FortiCamera
FortiCamera Cloud
FortiCare Elite
FortiCarrier
FortiCASB
FortiCentral
FortiClient
FortiClient Cloud
FortiCloud Services
FortiCNP
FortiConnect
FortiController
FortiConverter Service
FortiConverter Tool
FortiCore
FortiCWP
FortiDAST
FortiDB
FortiDDoS
FortiDDoS-F
FortiDeceptor
FortiDeceptor Private Cloud
FortiDeceptor Public Cloud
FortiDevSec
FortiDNS
FortiEDR
FortiExplorer
FortiExplorer Go
FortiExtender
FortiExtender Cloud
FortiFlex
FortiFone
FortiGate / FortiOS
FortiGate Cloud
FortiGate CNF
FortiGate Private Cloud
FortiGate Public Cloud
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiGSLB
FortiGuest
FortiHypervisor
FortiInsight
FortiInsight Cloud
FortiIPAM
FortiIsolator
FortiIsolator Public Cloud
FortiLAN Cloud
FortiMail
FortiMail Cloud
FortiManager
FortiManager Cloud
FortiManager Private Cloud
FortiManager Public Cloud
FortiMonitor
FortiMonitor 100F
FortiNAC
FortiNAC-F
FortiNDR
FortiNDR Cloud
FortiNDR Private Cloud
FortiNDR Public Cloud
FortiPAM
FortiPAM Private Cloud
FortiPAM Public Cloud
FortiPhish
FortiPlanner
FortiPolicy
FortiPortal
FortiPortal Public Cloud
FortiPresence
FortiPresence VM
FortiProxy
FortiProxy Private Cloud
FortiProxy Public Cloud
FortiRecon
FortiRecorder
FortiRPS
FortiSandbox
FortiSandbox Cloud
FortiSandbox Private Cloud
FortiSandbox Public Cloud
FortiSASE
FortiScan
FortiSIEM
FortiSIEM Cloud
FortiSOAR
FortiSOAR Cloud
FortiSwitch
FortiSwitch Manager
FortiTap
FortiTester
FortiTester Private Cloud
FortiTester Public Cloud
FortiToken
FortiToken Cloud
FortiTrust Identity
FortiVoice
FortiVoice Cloud
FortiVoice Private Cloud
FortiVoice Public Cloud
FortiWAN
FortiWAN Controller
FortiWeb
FortiWeb Cloud
FortiWeb Manager Private Cloud
FortiWeb Manager Public Cloud
FortiWeb Private Cloud
FortiWeb Public Cloud
FortiWLM
FortiZTP
IPS Engine
Managed FortiGate Service
Overlay-as-a-Service
Security Awareness and Training
SOCaaS
Wireless Controller
Ordering Guides
Document
Library
Product Pillars
Network Security
Network Security
FortiGate / FortiOS
FortiGate-5000
/
6000
/
7000
FortiProxy
NOC & SOC Management
FortiManager
/
FortiManager Cloud
FortiAnalyzer
/
FortiAnalyzer Cloud
FortiMonitor
FortiGate Cloud
Enterprise Networking
Secure SD-WAN
FortiLAN Cloud
FortiSwitch
FortiAP / FortiWiFi
FortiAP-U Series
FortiNAC-F
FortiExtender
/
FortiExtender Cloud
FortiAIOps
Business Communications
FortiFone
FortiVoice
/
FortiVoice Cloud
FortiRecorder
/
FortiCamera
Zero Trust Access
ZTNA
Zero Trust Network Access
FortiClient EMS
SASE
FortiSASE
Identity
FortiAuthenticator
FortiTrust Identity
FortiToken Cloud
FortiToken
Cloud Security
Hybrid Cloud Security
FortiGate Public Cloud
FortiGate Private Cloud
Flex-VM
Cloud Native Protection
FortiCNP
FortiDevSec
Web Application / API Protection
FortiWeb
/
FortiWeb Cloud
FortiADC
/
FortiGSLB
SAAS Security
FortiMail
/
FortiMail Cloud
FortiCASB
Security Operations
SOC Platform
FortiAnalyzer
/
FortiAnalyzer Cloud
FortiSIEM
/
FortiSIEM Cloud
FortiSOAR
FortiPhish
Advanced Threat Protection
FortiSandbox
/
FortiSandbox Cloud
FortiNDR
FortiDeceptor
FortiInsight
/
FortiInsight Cloud
FortiIsolator
Endpoint Security
FortiClient
/
FortiClient Cloud
FortiEDR
Best Practices
Solution Hubs
Curated links by solution
Cloud
FortiCloud
Public & Private Cloud
Popular Solutions
Secure SD-WAN
Zero Trust Network Access
Secure Access
Security Fabric
Tele-Working
Multi-Factor Authentication
FortiASIC
Operational Technology
MSSP
4-D Resources
Define, Design, Deploy, Demo
Secure SD-WAN
Zero Trust Network Access
Wireless
Switching
Secure Access Service Edge
Next Generation Firewall
Hardware Guides
Filter Products
FortiAnalyzer
FortiAnalyzer Big-Data
FortiADC
FortiAI
FortiAP / FortiWiFi
FortiAP U-Series
FortiAuthenticator
FortiCache
FortiCarrier
FortiController
FortiDDoS
FortiDDoS-F
FortiDeceptor
FortiEdge
FortiExtender
FortiGate
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiHypervisor
FortiIsolator
FortiMail
FortiManager
FortiNAC
FortiNDR
FortiProxy
FortiRecorder
FortiRPS
FortiSandbox
FortiSIEM
FortiSwitch
FortiTester
FortiToken
FortiVoice
FortiWAN
FortiWeb
FortiWLC
FortiWLM
Product A-Z
Filter Products
AscenLink
AV Engine
AWS Firewall Rules
FortiADC
FortiADC E Series
FortiADC Manager
FortiADC Private Cloud
FortiADC Public Cloud
FortiAIOps
FortiAnalyzer
FortiAnalyzer BigData
FortiAnalyzer BigData Private Cloud
FortiAnalyzer Cloud
FortiAnalyzer Private Cloud
FortiAnalyzer Public Cloud
FortiAP / FortiWiFi
FortiAP-U Series
FortiAuthenticator
FortiAuthenticator Private Cloud
FortiAuthenticator Public Cloud
FortiBalancer
FortiBridge
FortiCache
FortiCamera
FortiCamera Cloud
FortiCare Elite
FortiCarrier
FortiCASB
FortiCentral
FortiClient
FortiClient Cloud
FortiCloud Services
FortiCNP
FortiConnect
FortiController
FortiConverter Service
FortiConverter Tool
FortiCore
FortiCWP
FortiDAST
FortiDB
FortiDDoS
FortiDDoS-F
FortiDeceptor
FortiDeceptor Private Cloud
FortiDeceptor Public Cloud
FortiDevSec
FortiDNS
FortiEDR
FortiExplorer
FortiExplorer Go
FortiExtender
FortiExtender Cloud
FortiFlex
FortiFone
FortiGate / FortiOS
FortiGate Cloud
FortiGate CNF
FortiGate Private Cloud
FortiGate Public Cloud
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiGSLB
FortiGuest
FortiHypervisor
FortiInsight
FortiInsight Cloud
FortiIPAM
FortiIsolator
FortiIsolator Public Cloud
FortiLAN Cloud
FortiMail
FortiMail Cloud
FortiManager
FortiManager Cloud
FortiManager Private Cloud
FortiManager Public Cloud
FortiMonitor
FortiMonitor 100F
FortiNAC
FortiNAC-F
FortiNDR
FortiNDR Cloud
FortiNDR Private Cloud
FortiNDR Public Cloud
FortiPAM
FortiPAM Private Cloud
FortiPAM Public Cloud
FortiPhish
FortiPlanner
FortiPolicy
FortiPortal
FortiPortal Public Cloud
FortiPresence
FortiPresence VM
FortiProxy
FortiProxy Private Cloud
FortiProxy Public Cloud
FortiRecon
FortiRecorder
FortiRPS
FortiSandbox
FortiSandbox Cloud
FortiSandbox Private Cloud
FortiSandbox Public Cloud
FortiSASE
FortiScan
FortiSIEM
FortiSIEM Cloud
FortiSOAR
FortiSOAR Cloud
FortiSwitch
FortiSwitch Manager
FortiTap
FortiTester
FortiTester Private Cloud
FortiTester Public Cloud
FortiToken
FortiToken Cloud
FortiTrust Identity
FortiVoice
FortiVoice Cloud
FortiVoice Private Cloud
FortiVoice Public Cloud
FortiWAN
FortiWAN Controller
FortiWeb
FortiWeb Cloud
FortiWeb Manager Private Cloud
FortiWeb Manager Public Cloud
FortiWeb Private Cloud
FortiWeb Public Cloud
FortiWLM
FortiZTP
IPS Engine
Managed FortiGate Service
Overlay-as-a-Service
Security Awareness and Training
SOCaaS
Wireless Controller
Ordering Guides
Search documents and hardware ...
Version:
7.4.0
7.2.0
7.0.0
Version:
6.4.0
6.2.0
Table of Contents
About FortiGate-VM for GCP
Machine type support
Upgrading or downgrading a GCP instance to another machine type
Models
Licensing
Order types
Creating a support account
Migrating a FortiGate-VM instance between license types
Obtaining FortiCare-generated license and certificates for GCP PAYG instances
Obtaining FortiGate-VM image for GCP
Finding public FortiGate images
Using image family
Using private images
Copied private images
Single FortiGate-VM deployment
Deploying FortiGate-VM on Google Cloud Marketplace
Initially deploying the FortiGate-VM
Registering and downloading your license
Connecting to the FortiGate-VM
Deploying FortiGate-VM on Google Cloud Compute Engine
Obtaining the deployment image
Uploading the FortiGate deployment image to Google Cloud
Creating the FortiGate deployment image
Deploying the FortiGate-VM instance
Connecting to the FortiGate-VM
Configuring Google Cloud firewall rules
Configuring the second NIC on the FortiGate-VM
Configuring static routing in FortiGate-VM
Configuring static network settings
Assigning a static internal IP address in GCP
Configuring static addressing in FortiOS
Load balancer routes
MULTI_IP_SUBNET scheme
Deploying FortiGate-VM using Google Cloud SDK
Obtaining the deployment image
Uploading the deployment image to Google Cloud
Creating a FortiGate custom image
Deploying a FortiGate-VM instance
Bootstrapping FortiGate at initial bootup
Deploying FortiGate-VM using Terraform
High availability for FortiGate-VM on GCP
Deploying FortiGate-VM HA with SDN connector
Checking the prerequisites
Creating VPC networks and firewall rules
Deploying the primary FortiGate
Deploying the secondary FortiGate
Creating a GCP route table
Uploading the license and configuring network interfaces
Testing and troubleshooting
Protocol forwarding rule with SDN connector
Creating a target instance for each FortiGate-VM
Configuring the FortiGates
Testing the route and forwarding rule failover
Deploying FortiGate-VM HA with external and internal LB (web console)
FGCP in public cloud
Predeployment steps
Deploying FortiGate-VM instances
Reserving internal addresses
Creating instance groups
Creating the external LB
Creating the internal LB
Creating a custom route
Configure FortiGates networking
Configuring FortiGate clustering
Configure health check probe responders
Best practices and next steps
Deploying FortiGate-VM HA with external and internal LB (GCloud CLI)
FGCP in public cloud
Predeployment steps
Reserving internal addresses
Deploying FortiGate-VM instances
Creating instance groups
Creating the external LB
Creating the internal LB and custom route
Configure FortiGates networking
Configuring FortiGate clustering
Configure health check probe responders
Best practices and next steps
Additional documentation
SDN connector integration with GCP
Configuring GCP SDN connector using metadata IAM
GCP Kubernetes (GKE) SDN connector
Configuring GCP SDN Connector using service account
Creating a GCP service account
Multiple GCP projects in a single SDN connector
Troubleshooting GCP SDN Connector
Pipelined automation using Google Cloud function
Deploying auto scaling on GCP
Requirements
Deployment
Quotas
Terraform variables
Deployment information
Verify the deployment
Adding instances to the protected subnet
Destroying the cluster
Troubleshooting
Appendix
FortiGate Autoscale for GCP features
Architectural diagram
VPN for FortiGate-VM on GCP
Site-to-site IPsec VPNs between HA VPN on GCP
Packet mirroring
Creating VPC networks
Launching the FortiGate-VM instance
Creating an unmanaged instance group and load balancer
Configuring bidirectional VPC peering
Creating the packet mirroring policy
Verifying the configuration
Organization restrictions
SD-WAN transit routing with Google Network Connectivity Center
Prerequisites
Script execution for a single spoke
Configuring site-to-site VPN
Configuring the tunnel interfaces
Configuring BGP neighbors
Enabling dynamic routing mode
Completing post-deployment configuration
Deploying multiple spokes
Deploying resources in spoke VPC
Validating the configuration
Home
FortiGate Public Cloud 7.0.0
GCP Administration Guide
GCP Administration Guide
About FortiGate-VM for GCP
Machine type support
Upgrading or downgrading a GCP instance to another machine type
Models
Licensing
Order types
Creating a support account
Migrating a FortiGate-VM instance between license types
Obtaining FortiCare-generated license and certificates for GCP PAYG instances
Obtaining FortiGate-VM image for GCP
Finding public FortiGate images
Using image family
Using private images
Copied private images
Single FortiGate-VM deployment
Deploying FortiGate-VM on Google Cloud Marketplace
Initially deploying the FortiGate-VM
Registering and downloading your license
Connecting to the FortiGate-VM
Deploying FortiGate-VM on Google Cloud Compute Engine
Obtaining the deployment image
Uploading the FortiGate deployment image to Google Cloud
Creating the FortiGate deployment image
Deploying the FortiGate-VM instance
Connecting to the FortiGate-VM
Configuring Google Cloud firewall rules
Configuring the second NIC on the FortiGate-VM
Configuring static routing in FortiGate-VM
Configuring static network settings
Assigning a static internal IP address in GCP
Configuring static addressing in FortiOS
Load balancer routes
MULTI_IP_SUBNET scheme
Deploying FortiGate-VM using Google Cloud SDK
Obtaining the deployment image
Uploading the deployment image to Google Cloud
Creating a FortiGate custom image
Deploying a FortiGate-VM instance
Bootstrapping FortiGate at initial bootup
Deploying FortiGate-VM using Terraform
High availability for FortiGate-VM on GCP
Deploying FortiGate-VM HA with SDN connector
Checking the prerequisites
Creating VPC networks and firewall rules
Deploying the primary FortiGate
Deploying the secondary FortiGate
Creating a GCP route table
Uploading the license and configuring network interfaces
Testing and troubleshooting
Protocol forwarding rule with SDN connector
Creating a target instance for each FortiGate-VM
Configuring the FortiGates
Testing the route and forwarding rule failover
Deploying FortiGate-VM HA with external and internal LB (web console)
FGCP in public cloud
Predeployment steps
Deploying FortiGate-VM instances
Reserving internal addresses
Creating instance groups
Creating the external LB
Creating the internal LB
Creating a custom route
Configure FortiGates networking
Configuring FortiGate clustering
Configure health check probe responders
Best practices and next steps
Deploying FortiGate-VM HA with external and internal LB (GCloud CLI)
FGCP in public cloud
Predeployment steps
Reserving internal addresses
Deploying FortiGate-VM instances
Creating instance groups
Creating the external LB
Creating the internal LB and custom route
Configure FortiGates networking
Configuring FortiGate clustering
Configure health check probe responders
Best practices and next steps
Additional documentation
SDN connector integration with GCP
Configuring GCP SDN connector using metadata IAM
GCP Kubernetes (GKE) SDN connector
Configuring GCP SDN Connector using service account
Creating a GCP service account
Multiple GCP projects in a single SDN connector
Troubleshooting GCP SDN Connector
Pipelined automation using Google Cloud function
Deploying auto scaling on GCP
Requirements
Deployment
Quotas
Terraform variables
Deployment information
Verify the deployment
Adding instances to the protected subnet
Destroying the cluster
Troubleshooting
Appendix
FortiGate Autoscale for GCP features
Architectural diagram
VPN for FortiGate-VM on GCP
Site-to-site IPsec VPNs between HA VPN on GCP
Packet mirroring
Creating VPC networks
Launching the FortiGate-VM instance
Creating an unmanaged instance group and load balancer
Configuring bidirectional VPC peering
Creating the packet mirroring policy
Verifying the configuration
Organization restrictions
SD-WAN transit routing with Google Network Connectivity Center
Prerequisites
Script execution for a single spoke
Configuring site-to-site VPN
Configuring the tunnel interfaces
Configuring BGP neighbors
Enabling dynamic routing mode
Completing post-deployment configuration
Deploying multiple spokes
Deploying resources in spoke VPC
Validating the configuration
7.0.0
7.4.0
7.2.0
7.0.0
6.4.0
6.2.0
Download PDF
Copy Doc ID
2a566884-8679-11eb-9995-00505692583a:428946
Copy Link
Architectural diagram
Election of the pirmary instance
Previous
Next
Architectural diagram
Election of the pirmary instance
Previous
Next
Link
PDF
TOC