Fortinet white logo
Fortinet white logo

Azure vWAN SD-WAN NGFW Deployment Guide

7.6.0

Deploying FortiGate NVAs in a vWAN hub

Deploying FortiGate NVAs in a vWAN hub

In Azure Marketplace, deploy FortiGate network virtual machines (NVAs) in the virtual WAN (vWAN) hub.

The Scale Unit option controls the type and number of FortiGate NVAs created. See Order types in vWAN.

The FortiGate NVAs display as a group in FortiManager, and the name of the group in FortiManager is based on the FortiGate Name Prefix option in Azure.

To deploy FortiGate NVAs in vWAN hub:
  1. On Azure marketplace, deploy the aforementioned vWAN NVA application and set the following options:

  2. Click Next: FortiGate Secure SDWAN in Virtual WAN, and set the following options:

    Note

    Scale units cannot change dynamically. To use a different scale unit after deploying the NVAs, you must redeploy the NVAs.

    Each scale unit creates two FortiGate NVAs in the Microsoft Azure vWAN hub.

    For information about scale units, see Order types in vWAN.

    The FortiManager IP address must be public.

  3. To configure the internet-inbound deployment, do the following. This feature is in preview.
    1. Select Enable Internet Inbound Feature.
    2. The attached public IP address must be of a standard SKU. From the Public IP address for the Internet inbound Server Load balancer dropdown list, select the desired standard SKU IP address. If you are creating a new public IP address, select Create new > Standard.

    You can create additional public IP addresses after deployment on the Azure portal by going to vWAN > Hubs > NVA > Manage Configurations, then selecting Settings > Internet Inbound. This feature requires additional configuration. See Configuring internet inbound/DNAT policies.

  4. Note down the FortiGate BGP ASN setting. The default is 64512.
  5. Click Review + Create.
  6. Click Create.

Deploying FortiGate NVAs in a vWAN hub

Deploying FortiGate NVAs in a vWAN hub

In Azure Marketplace, deploy FortiGate network virtual machines (NVAs) in the virtual WAN (vWAN) hub.

The Scale Unit option controls the type and number of FortiGate NVAs created. See Order types in vWAN.

The FortiGate NVAs display as a group in FortiManager, and the name of the group in FortiManager is based on the FortiGate Name Prefix option in Azure.

To deploy FortiGate NVAs in vWAN hub:
  1. On Azure marketplace, deploy the aforementioned vWAN NVA application and set the following options:

  2. Click Next: FortiGate Secure SDWAN in Virtual WAN, and set the following options:

    Note

    Scale units cannot change dynamically. To use a different scale unit after deploying the NVAs, you must redeploy the NVAs.

    Each scale unit creates two FortiGate NVAs in the Microsoft Azure vWAN hub.

    For information about scale units, see Order types in vWAN.

    The FortiManager IP address must be public.

  3. To configure the internet-inbound deployment, do the following. This feature is in preview.
    1. Select Enable Internet Inbound Feature.
    2. The attached public IP address must be of a standard SKU. From the Public IP address for the Internet inbound Server Load balancer dropdown list, select the desired standard SKU IP address. If you are creating a new public IP address, select Create new > Standard.

    You can create additional public IP addresses after deployment on the Azure portal by going to vWAN > Hubs > NVA > Manage Configurations, then selecting Settings > Internet Inbound. This feature requires additional configuration. See Configuring internet inbound/DNAT policies.

  4. Note down the FortiGate BGP ASN setting. The default is 64512.
  5. Click Review + Create.
  6. Click Create.