Deployment procedures
Deployment requires the following steps:
- Use Azure Marketplace and FortiManager to create a vWAN, vWAN hub, and deploy FortiGate NVAs to the vWAN hub. See Deploying vWAN on Azure.
This step sets up the vWAN and FortiGate NVAs in the vWAN hub and adds a license to the FortiGate NVAs. The FortiGate NVAs will be the hub in our SD-WAN configuration.
This document does not describe how to deploy the FortiGate devices (either cloud or on-premise) that will be used for the branch devices (or spokes) in the SD-WAN network. See Prerequisites for SD-WAN configuration.
- Use FortiManager to configure SD-WAN on the deployed FortiGate NVAs (the hub) and deployed branch FortiGates (the spokes). See
Configuring SD-WAN on FortiManager .
This step adds the SD-WAN overlay of IPsec tunnels and BGP peering between the FortiGate NVA and the branch FortiGates. This configuration is sometimes called SD-WAN on-ramp.