Fortinet black logo

Creating a FortiGate model device

6.4.0
Copy Link
Copy Doc ID be779cd2-73cc-11ec-bdf2-fa163e15d75b:633632
Download PDF

Creating a FortiGate model device

In FortiManager, we will start by creating a model device for the FortiGate 60F. After the model device is created, we will use it again later when we assign templates to it for our FortiSwitch, FortiAP, and FortiExtender devices.

Tooltip

Some FortiGate model devices include a default policy to allow inside to outside access using a specified interface, for example WAN1.

As SD-WAN members may not use interfaces that are referenced directly in firewall policies, you must remove this reference by deleting the policy before installing the SD-WAN template.

This can be done manually through the CLI or GUI, or by installing a new policy package to the device that does not contain the default policy.

For more information on how to provision a FortiGate model device and the associated SD-WAN configuration (such as underlay, routing, overlay, SD-WAN and security), see the SD-WAN Deployment for MSSPs document.

To create a model device:
  1. In FortiManager, go to Device Manager > Device & Groups.
  2. Click Add Device. The Add Device wizard displays.
  3. Click Add Model Device, and add a model device for a FortiGate 60F, which we will use as our branch EDGE2:

    The model device will be used again in the following sections when we assign templates to it for our FortiSwitch, FortiAP, and FortiExtender devices.

Creating a FortiGate model device

In FortiManager, we will start by creating a model device for the FortiGate 60F. After the model device is created, we will use it again later when we assign templates to it for our FortiSwitch, FortiAP, and FortiExtender devices.

Tooltip

Some FortiGate model devices include a default policy to allow inside to outside access using a specified interface, for example WAN1.

As SD-WAN members may not use interfaces that are referenced directly in firewall policies, you must remove this reference by deleting the policy before installing the SD-WAN template.

This can be done manually through the CLI or GUI, or by installing a new policy package to the device that does not contain the default policy.

For more information on how to provision a FortiGate model device and the associated SD-WAN configuration (such as underlay, routing, overlay, SD-WAN and security), see the SD-WAN Deployment for MSSPs document.

To create a model device:
  1. In FortiManager, go to Device Manager > Device & Groups.
  2. Click Add Device. The Add Device wizard displays.
  3. Click Add Model Device, and add a model device for a FortiGate 60F, which we will use as our branch EDGE2:

    The model device will be used again in the following sections when we assign templates to it for our FortiSwitch, FortiAP, and FortiExtender devices.