Fortinet black logo

CLI Reference

config system sdn-connector

config system sdn-connector

Configure connection to SDN Connector.

config system sdn-connector
    Description: Configure connection to SDN Connector.
    edit <name>
        set access-key {string}
        set api-key {password}
        set azure-region [global|china|...]
        set client-id {string}
        set client-secret {password}
        set compartment-id {string}
        set compute-generation {integer}
        set domain {string}
        config external-account-list
            Description: Configure AWS external account list.
            edit <role-arn>
                set role-arn {string}
                set external-id {string}
                set region-list <region1>, <region2>, ...
            next
        end
        config external-ip
            Description: Configure GCP external IP.
            edit <name>
                set name {string}
            next
        end
        config forwarding-rule
            Description: Configure GCP forwarding rule.
            edit <rule-name>
                set rule-name {string}
                set target {string}
            next
        end
        config gcp-project-list
            Description: Configure GCP project list.
            edit <id>
                set id {string}
                set gcp-zone-list <name1>, <name2>, ...
            next
        end
        set group-name {string}
        set ha-status [disable|enable]
        set ibm-region [dallas|washington-dc|...]
        set login-endpoint {string}
        set name {string}
        config nic
            Description: Configure Azure network interface.
            edit <name>
                set name {string}
                config ip
                    Description: Configure IP configuration.
                    edit <name>
                        set name {string}
                        set public-ip {string}
                        set resource-group {string}
                    next
                end
            next
        end
        set oci-cert {string}
        set oci-fingerprint {string}
        set oci-region {string}
        set oci-region-type [commercial|government]
        set password {password_aes256}
        set private-key {user}
        set region {string}
        set resource-group {string}
        set resource-url {string}
        config route
            Description: Configure GCP route.
            edit <name>
                set name {string}
            next
        end
        config route-table
            Description: Configure Azure route table.
            edit <name>
                set name {string}
                set subscription-id {string}
                set resource-group {string}
                config route
                    Description: Configure Azure route.
                    edit <name>
                        set name {string}
                        set next-hop {string}
                    next
                end
            next
        end
        set secret-key {password}
        set secret-token {user}
        set server {string}
        set server-list <ip1>, <ip2>, ...
        set server-port {integer}
        set service-account {string}
        set status [disable|enable]
        set subscription-id {string}
        set tenant-id {string}
        set type [aci|alicloud|...]
        set update-interval {integer}
        set use-metadata-iam [disable|enable]
        set user-id {string}
        set username {string}
        set vcenter-password {password_aes256}
        set vcenter-server {string}
        set vcenter-username {string}
        set verify-certificate [disable|enable]
        set vpc-id {string}
    next
end

config system sdn-connector

Parameter

Description

Type

Size

Default

access-key

AWS / ACS access key ID.

string

Not Specified

api-key

IBM cloud API key or service ID API key.

password

Not Specified

azure-region

Azure server region.

option

-

global

Option

Description

global

Global Azure Server.

china

China Azure Server.

germany

Germany Azure Server.

usgov

US Government Azure Server.

local

Azure Stack Local Server.

client-id

Azure client ID (application ID).

string

Not Specified

client-secret

Azure client secret (application key).

password

Not Specified

compartment-id

Compartment ID.

string

Not Specified

compute-generation

Compute generation for IBM cloud infrastructure.

integer

Minimum value: 1 Maximum value: 2

2

domain

Domain name.

string

Not Specified

group-name

Group name of computers.

string

Not Specified

ha-status

Enable/disable use for FortiGate HA service.

option

-

disable

Option

Description

disable

Disable use for FortiGate HA service.

enable

Enable use for FortiGate HA service.

ibm-region

IBM cloud region name.

option

-

dallas

Option

Description

dallas

US South (Dallas) Public Endpoint.

washington-dc

US East (Washington DC) Public Endpoint.

london

United Kingdom (London) Public Endpoint.

frankfurt

Germany (Frankfurt) Public Endpoint.

sydney

Australia (Sydney) Public Endpoint.

tokyo

Japan (Tokyo) Public Endpoint.

osaka

Japan (Osaka) Public Endpoint.

toronto

Canada (Toronto) Public Endpoint.

sao-paulo

Brazil (Sao Paulo) Public Endpoint.

login-endpoint

Azure Stack login endpoint.

string

Not Specified

name

SDN connector name.

string

Not Specified

oci-cert

OCI certificate.

string

Not Specified

oci-fingerprint

OCI pubkey fingerprint.

string

Not Specified

oci-region

OCI server region.

string

Not Specified

oci-region-type

OCI region type.

option

-

commercial

Option

Description

commercial

Commercial region.

government

Government region.

password

Password of the remote SDN connector as login credentials.

password_aes256

Not Specified

private-key

Private key of GCP service account.

user

Not Specified

region

AWS / ACS region name.

string

Not Specified

resource-group

Azure resource group.

string

Not Specified

resource-url

Azure Stack resource URL.

string

Not Specified

secret-key

AWS / ACS secret access key.

password

Not Specified

secret-token

Secret token of Kubernetes service account.

user

Not Specified

server

Server address of the remote SDN connector.

string

Not Specified

server-list <ip>

Server address list of the remote SDN connector.

IPv4 address.

string

Maximum length: 15

server-port

Port number of the remote SDN connector.

integer

Minimum value: 0 Maximum value: 65535

0

service-account

GCP service account email.

string

Not Specified

status

Enable/disable connection to the remote SDN connector.

option

-

enable

Option

Description

disable

Disable connection to this SDN Connector.

enable

Enable connection to this SDN Connector.

subscription-id

Azure subscription ID.

string

Not Specified

tenant-id

Tenant ID (directory ID).

string

Not Specified

type

Type of SDN connector.

option

-

aws

Option

Description

aci

Application Centric Infrastructure (ACI).

alicloud

AliCloud Service (ACS).

aws

Amazon Web Services (AWS).

azure

Microsoft Azure.

gcp

Google Cloud Platform (GCP).

nsx

VMware NSX.

nuage

Nuage VSP.

oci

Oracle Cloud Infrastructure.

openstack

OpenStack.

kubernetes

Kubernetes.

vmware

VMware vSphere (vCenter & ESXi).

sepm

Symantec Endpoint Protection Manager.

aci-direct

Application Centric Infrastructure (ACI Direct Connection).

ibm

IBM Cloud Infrastructure.

nutanix

Nutanix Prism Central.

update-interval

Dynamic object update interval.

integer

Minimum value: 0 Maximum value: 3600

60

use-metadata-iam

Enable/disable use of IAM role from metadata to call API.

option

-

disable

Option

Description

disable

Disable using IAM role to call API.

enable

Enable using IAM role to call API.

user-id

User ID.

string

Not Specified

username

Username of the remote SDN connector as login credentials.

string

Not Specified

vcenter-password

vCenter server password for NSX quarantine.

password_aes256

Not Specified

vcenter-server

vCenter server address for NSX quarantine.

string

Not Specified

vcenter-username

vCenter server username for NSX quarantine.

string

Not Specified

verify-certificate

Enable/disable server certificate verification.

option

-

enable

Option

Description

disable

Disable server certificate verification.

enable

Enable server certificate verification.

vpc-id

AWS VPC ID.

string

Not Specified

config external-account-list

Parameter

Description

Type

Size

Default

role-arn

AWS role ARN to assume.

string

Not Specified

external-id

AWS external ID.

string

Not Specified

region-list <region>

AWS region name list.

AWS region name.

string

Maximum length: 31

config external-ip

Parameter

Description

Type

Size

Default

name

External IP name.

string

Not Specified

config forwarding-rule

Parameter

Description

Type

Size

Default

rule-name

Forwarding rule name.

string

Not Specified

target

Target instance name.

string

Not Specified

config gcp-project-list

Parameter

Description

Type

Size

Default

id

GCP project ID.

string

Not Specified

gcp-zone-list <name>

Configure GCP zone list.

GCP zone name.

string

Maximum length: 127

config nic

Parameter

Description

Type

Size

Default

name

Network interface name.

string

Not Specified

config ip

Parameter

Description

Type

Size

Default

name

IP configuration name.

string

Not Specified

public-ip

Public IP name.

string

Not Specified

resource-group

Resource group of Azure public IP.

string

Not Specified

config route

Parameter

Description

Type

Size

Default

name

Route name.

string

Not Specified

config route

Parameter

Description

Type

Size

Default

name

Route name.

string

Not Specified

next-hop

Next hop address.

string

Not Specified

config route-table

Parameter

Description

Type

Size

Default

name

Route table name.

string

Not Specified

subscription-id

Subscription ID of Azure route table.

string

Not Specified

resource-group

Resource group of Azure route table.

string

Not Specified

config route

Parameter

Description

Type

Size

Default

name

Route name.

string

Not Specified

config route

Parameter

Description

Type

Size

Default

name

Route name.

string

Not Specified

next-hop

Next hop address.

string

Not Specified

config system sdn-connector

Configure connection to SDN Connector.

config system sdn-connector
    Description: Configure connection to SDN Connector.
    edit <name>
        set access-key {string}
        set api-key {password}
        set azure-region [global|china|...]
        set client-id {string}
        set client-secret {password}
        set compartment-id {string}
        set compute-generation {integer}
        set domain {string}
        config external-account-list
            Description: Configure AWS external account list.
            edit <role-arn>
                set role-arn {string}
                set external-id {string}
                set region-list <region1>, <region2>, ...
            next
        end
        config external-ip
            Description: Configure GCP external IP.
            edit <name>
                set name {string}
            next
        end
        config forwarding-rule
            Description: Configure GCP forwarding rule.
            edit <rule-name>
                set rule-name {string}
                set target {string}
            next
        end
        config gcp-project-list
            Description: Configure GCP project list.
            edit <id>
                set id {string}
                set gcp-zone-list <name1>, <name2>, ...
            next
        end
        set group-name {string}
        set ha-status [disable|enable]
        set ibm-region [dallas|washington-dc|...]
        set login-endpoint {string}
        set name {string}
        config nic
            Description: Configure Azure network interface.
            edit <name>
                set name {string}
                config ip
                    Description: Configure IP configuration.
                    edit <name>
                        set name {string}
                        set public-ip {string}
                        set resource-group {string}
                    next
                end
            next
        end
        set oci-cert {string}
        set oci-fingerprint {string}
        set oci-region {string}
        set oci-region-type [commercial|government]
        set password {password_aes256}
        set private-key {user}
        set region {string}
        set resource-group {string}
        set resource-url {string}
        config route
            Description: Configure GCP route.
            edit <name>
                set name {string}
            next
        end
        config route-table
            Description: Configure Azure route table.
            edit <name>
                set name {string}
                set subscription-id {string}
                set resource-group {string}
                config route
                    Description: Configure Azure route.
                    edit <name>
                        set name {string}
                        set next-hop {string}
                    next
                end
            next
        end
        set secret-key {password}
        set secret-token {user}
        set server {string}
        set server-list <ip1>, <ip2>, ...
        set server-port {integer}
        set service-account {string}
        set status [disable|enable]
        set subscription-id {string}
        set tenant-id {string}
        set type [aci|alicloud|...]
        set update-interval {integer}
        set use-metadata-iam [disable|enable]
        set user-id {string}
        set username {string}
        set vcenter-password {password_aes256}
        set vcenter-server {string}
        set vcenter-username {string}
        set verify-certificate [disable|enable]
        set vpc-id {string}
    next
end

config system sdn-connector

Parameter

Description

Type

Size

Default

access-key

AWS / ACS access key ID.

string

Not Specified

api-key

IBM cloud API key or service ID API key.

password

Not Specified

azure-region

Azure server region.

option

-

global

Option

Description

global

Global Azure Server.

china

China Azure Server.

germany

Germany Azure Server.

usgov

US Government Azure Server.

local

Azure Stack Local Server.

client-id

Azure client ID (application ID).

string

Not Specified

client-secret

Azure client secret (application key).

password

Not Specified

compartment-id

Compartment ID.

string

Not Specified

compute-generation

Compute generation for IBM cloud infrastructure.

integer

Minimum value: 1 Maximum value: 2

2

domain

Domain name.

string

Not Specified

group-name

Group name of computers.

string

Not Specified

ha-status

Enable/disable use for FortiGate HA service.

option

-

disable

Option

Description

disable

Disable use for FortiGate HA service.

enable

Enable use for FortiGate HA service.

ibm-region

IBM cloud region name.

option

-

dallas

Option

Description

dallas

US South (Dallas) Public Endpoint.

washington-dc

US East (Washington DC) Public Endpoint.

london

United Kingdom (London) Public Endpoint.

frankfurt

Germany (Frankfurt) Public Endpoint.

sydney

Australia (Sydney) Public Endpoint.

tokyo

Japan (Tokyo) Public Endpoint.

osaka

Japan (Osaka) Public Endpoint.

toronto

Canada (Toronto) Public Endpoint.

sao-paulo

Brazil (Sao Paulo) Public Endpoint.

login-endpoint

Azure Stack login endpoint.

string

Not Specified

name

SDN connector name.

string

Not Specified

oci-cert

OCI certificate.

string

Not Specified

oci-fingerprint

OCI pubkey fingerprint.

string

Not Specified

oci-region

OCI server region.

string

Not Specified

oci-region-type

OCI region type.

option

-

commercial

Option

Description

commercial

Commercial region.

government

Government region.

password

Password of the remote SDN connector as login credentials.

password_aes256

Not Specified

private-key

Private key of GCP service account.

user

Not Specified

region

AWS / ACS region name.

string

Not Specified

resource-group

Azure resource group.

string

Not Specified

resource-url

Azure Stack resource URL.

string

Not Specified

secret-key

AWS / ACS secret access key.

password

Not Specified

secret-token

Secret token of Kubernetes service account.

user

Not Specified

server

Server address of the remote SDN connector.

string

Not Specified

server-list <ip>

Server address list of the remote SDN connector.

IPv4 address.

string

Maximum length: 15

server-port

Port number of the remote SDN connector.

integer

Minimum value: 0 Maximum value: 65535

0

service-account

GCP service account email.

string

Not Specified

status

Enable/disable connection to the remote SDN connector.

option

-

enable

Option

Description

disable

Disable connection to this SDN Connector.

enable

Enable connection to this SDN Connector.

subscription-id

Azure subscription ID.

string

Not Specified

tenant-id

Tenant ID (directory ID).

string

Not Specified

type

Type of SDN connector.

option

-

aws

Option

Description

aci

Application Centric Infrastructure (ACI).

alicloud

AliCloud Service (ACS).

aws

Amazon Web Services (AWS).

azure

Microsoft Azure.

gcp

Google Cloud Platform (GCP).

nsx

VMware NSX.

nuage

Nuage VSP.

oci

Oracle Cloud Infrastructure.

openstack

OpenStack.

kubernetes

Kubernetes.

vmware

VMware vSphere (vCenter & ESXi).

sepm

Symantec Endpoint Protection Manager.

aci-direct

Application Centric Infrastructure (ACI Direct Connection).

ibm

IBM Cloud Infrastructure.

nutanix

Nutanix Prism Central.

update-interval

Dynamic object update interval.

integer

Minimum value: 0 Maximum value: 3600

60

use-metadata-iam

Enable/disable use of IAM role from metadata to call API.

option

-

disable

Option

Description

disable

Disable using IAM role to call API.

enable

Enable using IAM role to call API.

user-id

User ID.

string

Not Specified

username

Username of the remote SDN connector as login credentials.

string

Not Specified

vcenter-password

vCenter server password for NSX quarantine.

password_aes256

Not Specified

vcenter-server

vCenter server address for NSX quarantine.

string

Not Specified

vcenter-username

vCenter server username for NSX quarantine.

string

Not Specified

verify-certificate

Enable/disable server certificate verification.

option

-

enable

Option

Description

disable

Disable server certificate verification.

enable

Enable server certificate verification.

vpc-id

AWS VPC ID.

string

Not Specified

config external-account-list

Parameter

Description

Type

Size

Default

role-arn

AWS role ARN to assume.

string

Not Specified

external-id

AWS external ID.

string

Not Specified

region-list <region>

AWS region name list.

AWS region name.

string

Maximum length: 31

config external-ip

Parameter

Description

Type

Size

Default

name

External IP name.

string

Not Specified

config forwarding-rule

Parameter

Description

Type

Size

Default

rule-name

Forwarding rule name.

string

Not Specified

target

Target instance name.

string

Not Specified

config gcp-project-list

Parameter

Description

Type

Size

Default

id

GCP project ID.

string

Not Specified

gcp-zone-list <name>

Configure GCP zone list.

GCP zone name.

string

Maximum length: 127

config nic

Parameter

Description

Type

Size

Default

name

Network interface name.

string

Not Specified

config ip

Parameter

Description

Type

Size

Default

name

IP configuration name.

string

Not Specified

public-ip

Public IP name.

string

Not Specified

resource-group

Resource group of Azure public IP.

string

Not Specified

config route

Parameter

Description

Type

Size

Default

name

Route name.

string

Not Specified

config route

Parameter

Description

Type

Size

Default

name

Route name.

string

Not Specified

next-hop

Next hop address.

string

Not Specified

config route-table

Parameter

Description

Type

Size

Default

name

Route table name.

string

Not Specified

subscription-id

Subscription ID of Azure route table.

string

Not Specified

resource-group

Resource group of Azure route table.

string

Not Specified

config route

Parameter

Description

Type

Size

Default

name

Route name.

string

Not Specified

config route

Parameter

Description

Type

Size

Default

name

Route name.

string

Not Specified

next-hop

Next hop address.

string

Not Specified