Fortinet black logo

AWS Administration Guide

Creating the GWLB and registering targets

Creating the GWLB and registering targets

To create the GWLB and register targets:
  1. Go to Compute > EC2 Dashboard > Load Balancing > Load Balancers.
  2. Click Create Load Balancer, then Gateway Load Balancer.
  3. Configure the gateway load balancer (GWLB):
    1. From the IP address type dropdown list, select ipv4.
    2. From the VPC dropdown list, select the security VPC, where the FortiGate is deployed.
    3. From the Availability Zones dropdown list, select the AZ and subnet where the FortiGate is deployed. This example selects the private subnet where the FortiGate port2 is mapped to. In this example, you can enable multiple VDOMs (only available on BYOL instances) or split-task VDOMs (available on BYOL and on-demand instances), and port2 is mapped to the traffic-handling VDOM. You then create the Geneve interface on port2 to handle the traffic that has been redirected via the GWLB. See Post-deployment configuration

      .

  4. Under IP Listeners Routing, click Create Target Group to configure a target group:
    1. For Target Type, select IP Address.
    2. In the Target Group Name field, enter the desired name.
    3. For Protocol, select GENEVE.
    4. In the Port field, enter 6081.
    5. For VPC, select the VPC where you have deployed or will deploy the GWLB. In this example, the desired VPC is the security VPC.
    6. Under Health Checks, configure the following:
      1. For Protocol, select TCP.
      2. Override the Advanced Health Check Settings > Port setting to 443.
  5. Register the targets during target group creation:
    1. In the IP field, enter the FortiGate IP address. In this example, you would enter the FortiGate port2 IP address.
    2. Click Include as pending below.
    3. Click Create Target Group.
  6. Ensure that cross-zone LB is enabled:
    1. Go to Compute > EC2 Dashboard > Load Balancing > Load Balancers.
    2. Select the newly created LB.
    3. On the Attributes tab, edit the attributes and ensure that cross-zone LB is enabled.

Creating the GWLB and registering targets

To create the GWLB and register targets:
  1. Go to Compute > EC2 Dashboard > Load Balancing > Load Balancers.
  2. Click Create Load Balancer, then Gateway Load Balancer.
  3. Configure the gateway load balancer (GWLB):
    1. From the IP address type dropdown list, select ipv4.
    2. From the VPC dropdown list, select the security VPC, where the FortiGate is deployed.
    3. From the Availability Zones dropdown list, select the AZ and subnet where the FortiGate is deployed. This example selects the private subnet where the FortiGate port2 is mapped to. In this example, you can enable multiple VDOMs (only available on BYOL instances) or split-task VDOMs (available on BYOL and on-demand instances), and port2 is mapped to the traffic-handling VDOM. You then create the Geneve interface on port2 to handle the traffic that has been redirected via the GWLB. See Post-deployment configuration

      .

  4. Under IP Listeners Routing, click Create Target Group to configure a target group:
    1. For Target Type, select IP Address.
    2. In the Target Group Name field, enter the desired name.
    3. For Protocol, select GENEVE.
    4. In the Port field, enter 6081.
    5. For VPC, select the VPC where you have deployed or will deploy the GWLB. In this example, the desired VPC is the security VPC.
    6. Under Health Checks, configure the following:
      1. For Protocol, select TCP.
      2. Override the Advanced Health Check Settings > Port setting to 443.
  5. Register the targets during target group creation:
    1. In the IP field, enter the FortiGate IP address. In this example, you would enter the FortiGate port2 IP address.
    2. Click Include as pending below.
    3. Click Create Target Group.
  6. Ensure that cross-zone LB is enabled:
    1. Go to Compute > EC2 Dashboard > Load Balancing > Load Balancers.
    2. Select the newly created LB.
    3. On the Attributes tab, edit the attributes and ensure that cross-zone LB is enabled.