Cisco ACI SDN connector using a standalone connector

Cisco ACI (Application Centric Infrastructure) SDN connectors can be used in dynamic firewall addresses.

The Fortinet SDN Connector for Cisco ACI and Nuage Networks is a standalone connector that connects to SDN controllers within Cisco ACI and Nuage Networks. You must configure a connection to the Fortinet SDN connector in FortiOS to query the dynamic addresses.


This topic describes one of multiple configuration methods available with this SDN connector type. See the More Links section on the right sidebar for other methods.

To configure a Cisco ACI connector in the GUI:
  1. Create the Cisco ACI SDN connector:
    1. Go to Security Fabric > External Connectors and click Create New.
    2. In the Private SDN section, click Application Centric Infrastructure (ACI).
    3. In the Cisco ACI Connector section, for Type, select Fortinet SDN Connector and configure the remaining settings as needed.
    4. Click OK.

  2. Create the dynamic firewall address for the connector:
    1. Go to Policy & Objects > Addresses and click Create New > Address.
    2. Configure the following settings:
      1. For Type, select Dynamic.
      2. For Sub Type, select Fabric Connector Address.
      3. For SDN Connector, select the first ACI connector.
      4. Configure the remaining settings as needed.
    3. Click OK.

To verify the dynamic firewall IPs are resolved by the SDN connector in the GUI: