Fortinet white logo
Fortinet white logo

Azure vWAN SD-WAN NGFW Deployment Guide

7.2.0

Enabling Azure routing policy

Enabling Azure routing policy

Note

When deploying only SD-WAN, it's not necessary to enable routing intent. Skip this procedure and go to Authorizing FortiGate NVAs on FortiManager.

To enable Azure routing policy:
  1. On the Azure portal, go to VirtualWAN > Hub > Routing.

    The Routing options are displayed.

  2. Click Routing Intent and Routing Policies, and set the following options:
    • Select the next hop for private traffic or Internet-bound traffic.
    • Ensure that Private Traffic is set to the address space from the peered VNET from Peering a vNET to the virtual WAN hub.

    This example shows forwarding all the required RFC 1918 Addresses Internal Traffic to the Network Virtual Appliance under Routing Intent and Routing Policies.

    Note

    Ensure that you include the Address space from the peered VNET (see Peering a vNET to the virtual WAN hub) in Private Traffic.

  3. Click Save.

Enabling Azure routing policy

Enabling Azure routing policy

Note

When deploying only SD-WAN, it's not necessary to enable routing intent. Skip this procedure and go to Authorizing FortiGate NVAs on FortiManager.

To enable Azure routing policy:
  1. On the Azure portal, go to VirtualWAN > Hub > Routing.

    The Routing options are displayed.

  2. Click Routing Intent and Routing Policies, and set the following options:
    • Select the next hop for private traffic or Internet-bound traffic.
    • Ensure that Private Traffic is set to the address space from the peered VNET from Peering a vNET to the virtual WAN hub.

    This example shows forwarding all the required RFC 1918 Addresses Internal Traffic to the Network Virtual Appliance under Routing Intent and Routing Policies.

    Note

    Ensure that you include the Address space from the peered VNET (see Peering a vNET to the virtual WAN hub) in Private Traffic.

  3. Click Save.