Fortinet white logo
Fortinet white logo

Azure vWAN SD-WAN NGFW Deployment Guide

7.4.0

Configuring SD-WAN on FortiManager

Configuring SD-WAN on FortiManager

After the FortiGate NVAs for the vWAN hub and FortiGate units for branch locations are configured and managed by FortiManager, you are ready to use FortiManager to configure a new SD-WAN region. FortiGate NVAs are the hub, and branch FortiGates are the spokes in the SD-WAN configuration.

See also Prerequisites for SD-WAN configuration.

Following is a summary of the FortiManager steps required to configure a new SD-WAN region with Azure vWAN:

  1. Plan your network. See Planning the network.
  2. Create an SD-WAN overlay template. See Creating an SD-WAN overlay template.
  3. Verify the SD-WAN overlay template creation. See Verifying the SD-WAN overlay template.
  4. Edit the SD-WAN template for branch devices to modify interface members. See Editing the SD-WAN template for branch devices.
  5. Configure branch to vWAN hub rules. See Configuring branch to vWAN rules.
  6. Verify template group content. See Verifying the template group includes the SD-WAN template.
  7. Assign metadata values to each branch device. See Assigning metadata values to branch devices.
  8. Create a CLI template to address Azure DHCP assignments. See Creating a CLI template for branch devices with DHCP gateway assignments.
  9. Add Azure BGP neighbors. See Adding Azure router BGP neighbors.
  10. (Optional) Create policy packages and policies. See (Optional) Creating policy packages.
  11. Ensure the installation targets for the policy packages are correct. See Checking installation targets for policy packages.
  12. Install device settings. See Installing device settings.

Configuring SD-WAN on FortiManager

Configuring SD-WAN on FortiManager

After the FortiGate NVAs for the vWAN hub and FortiGate units for branch locations are configured and managed by FortiManager, you are ready to use FortiManager to configure a new SD-WAN region. FortiGate NVAs are the hub, and branch FortiGates are the spokes in the SD-WAN configuration.

See also Prerequisites for SD-WAN configuration.

Following is a summary of the FortiManager steps required to configure a new SD-WAN region with Azure vWAN:

  1. Plan your network. See Planning the network.
  2. Create an SD-WAN overlay template. See Creating an SD-WAN overlay template.
  3. Verify the SD-WAN overlay template creation. See Verifying the SD-WAN overlay template.
  4. Edit the SD-WAN template for branch devices to modify interface members. See Editing the SD-WAN template for branch devices.
  5. Configure branch to vWAN hub rules. See Configuring branch to vWAN rules.
  6. Verify template group content. See Verifying the template group includes the SD-WAN template.
  7. Assign metadata values to each branch device. See Assigning metadata values to branch devices.
  8. Create a CLI template to address Azure DHCP assignments. See Creating a CLI template for branch devices with DHCP gateway assignments.
  9. Add Azure BGP neighbors. See Adding Azure router BGP neighbors.
  10. (Optional) Create policy packages and policies. See (Optional) Creating policy packages.
  11. Ensure the installation targets for the policy packages are correct. See Checking installation targets for policy packages.
  12. Install device settings. See Installing device settings.