In FortiOS 6.2, support has been added for non-VM resources (load balancers and application gateways) to Azure SDN connectors, which can be configured in the GUI or CLI.
Prior to FortiOS 6.2, only IP addresses of VMs were supported.
The tag filter now supports the VM, VMSS, application gateway (applicationgateway=<name>), and load balancer types (loadbalancer=<name>).
VPN gateways are currently not supported.
- Go to Policy & Objects > Addresses.
- Click Create New > Address and enter a name.
- Configure the following settings:
- For Type, select Dynamic.
- For Sub Type, select Fabric Connector Address.
- For SDN Connector, select azure-dev.
- For SDN address type, select All.
- For Filter, enter
- Click OK.
The corresponding IP addresses are dynamically updated and resolved after applying the tag filter.
- In the address table, hover over the address to view what IP it resolves to:
- In Azure, verify to confirm the IP address matches:
config firewall address edit "taginternetfacinglb" set type dynamic set sdn "azure-dev" set filter "Tag.devlb=lbkeyvalue" set sdn-addr-type all next end