Azure SDN connector using service principal
FortiOS automatically updates dynamic addresses for Azure using Azure SDN connector, including mapping attributes from Azure instances to dynamic address groups in FortiOS.
![]() |
This topic describes one of multiple configuration methods available with this SDN connector type. See the More Links section on the right sidebar for other methods. |
To configure the Azure SDN connector using service principal:
- Create an Azure SDN connector:
- Go to Security Fabric > External Connectors and click Create New.
- Select Microsoft Azure.
- Configure the connector. See Azure SDN connector service principal configuration requirements:
- Click OK.
- Create a dynamic firewall address for the Azure connector.
- Go to Policy & Objects > Addresses and click Create New > Address.
- From the Type dropdown list, select Dynamic.
- From the Sub Type dropdown list, select Fabric Connector Address.
- From the SDN Connector dropdown list, select the Azure SDN connector.
- In the Filter field, add filters as desired. The Azure SDN connector supports the following filters:
vm=<VM name>
securitygroup=<nsg id>
vnet=<VNet id>
subnet=<subnet id>
vmss=<VM scale set>
tag.<key>=<value>
servicetag=<value>
tag.<key>=<value>
- Click OK.
- Hover the cursor over the address name to see the dynamic IP addresses that the connector resolves.