Fortinet white logo
Fortinet white logo

CLI Reference

config system sdn-vpn

config system sdn-vpn

Configure public cloud VPN service.

config system sdn-vpn
    Description: Configure public cloud VPN service.
    edit <name>
        set bgp-as {integer}
        set cgw-gateway {ipv4-address-any}
        set cgw-name {string}
        set code {integer}
        set internal-interface {string}
        set local-cidr {ipv4-classnet}
        set nat-traversal [disable|enable]
        set psksecret {password-3}
        set remote-cidr {ipv4-classnet}
        set remote-type [vgw|tgw]
        set routing-type [static|dynamic]
        set sdn {string}
        set status {integer}
        set subnet-id {string}
        set tgw-id {string}
        set tunnel-interface {string}
        set type {integer}
        set vgw-id {string}
    next
end

config system sdn-vpn

Parameter

Description

Type

Size

Default

bgp-as

BGP Router AS number.

integer

Minimum value: 1 Maximum value: 4294967295

65000

cgw-gateway

Public IP address of the customer gateway.

ipv4-address-any

Not Specified

0.0.0.0

cgw-name

AWS customer gateway name to be created.

string

Maximum length: 35

code

SDN VPN error code. Read-only.

integer

Minimum value: 0 Maximum value: 255

0

internal-interface

Internal interface with local subnet.

string

Maximum length: 15

local-cidr

Local subnet address and subnet mask.

ipv4-classnet

Not Specified

0.0.0.0 0.0.0.0

name

Public cloud VPN name.

string

Maximum length: 35

nat-traversal

Enable/disable use for NAT traversal. Please enable if your FortiGate device is behind a NAT/PAT device.

option

-

enable

Option

Description

disable

Disable NAT traversal.

enable

Enable NAT traversal.

psksecret

Pre-shared secret for PSK authentication. Auto-generated if not specified

password-3

Not Specified

remote-cidr

Remote subnet address and subnet mask.

ipv4-classnet

Not Specified

0.0.0.0 0.0.0.0

remote-type

Type of remote device.

option

-

vgw

Option

Description

vgw

Virtual private gateway.

tgw

Transit gateway.

routing-type

Type of routing.

option

-

dynamic

Option

Description

static

Static routing.

dynamic

Dynamic routing.

sdn

SDN connector name.

string

Maximum length: 35

status

SDN VPN status. Read-only.

integer

Minimum value: 0 Maximum value: 255

0

subnet-id

AWS subnet id for TGW route propagation.

string

Maximum length: 63

tgw-id

Transit gateway id.

string

Maximum length: 63

tunnel-interface

Tunnel interface with public IP.

string

Maximum length: 15

type

SDN VPN type. Read-only.

integer

Minimum value: 0 Maximum value: 65535

0

vgw-id

Virtual private gateway id.

string

Maximum length: 63

config system sdn-vpn

config system sdn-vpn

Configure public cloud VPN service.

config system sdn-vpn
    Description: Configure public cloud VPN service.
    edit <name>
        set bgp-as {integer}
        set cgw-gateway {ipv4-address-any}
        set cgw-name {string}
        set code {integer}
        set internal-interface {string}
        set local-cidr {ipv4-classnet}
        set nat-traversal [disable|enable]
        set psksecret {password-3}
        set remote-cidr {ipv4-classnet}
        set remote-type [vgw|tgw]
        set routing-type [static|dynamic]
        set sdn {string}
        set status {integer}
        set subnet-id {string}
        set tgw-id {string}
        set tunnel-interface {string}
        set type {integer}
        set vgw-id {string}
    next
end

config system sdn-vpn

Parameter

Description

Type

Size

Default

bgp-as

BGP Router AS number.

integer

Minimum value: 1 Maximum value: 4294967295

65000

cgw-gateway

Public IP address of the customer gateway.

ipv4-address-any

Not Specified

0.0.0.0

cgw-name

AWS customer gateway name to be created.

string

Maximum length: 35

code

SDN VPN error code. Read-only.

integer

Minimum value: 0 Maximum value: 255

0

internal-interface

Internal interface with local subnet.

string

Maximum length: 15

local-cidr

Local subnet address and subnet mask.

ipv4-classnet

Not Specified

0.0.0.0 0.0.0.0

name

Public cloud VPN name.

string

Maximum length: 35

nat-traversal

Enable/disable use for NAT traversal. Please enable if your FortiGate device is behind a NAT/PAT device.

option

-

enable

Option

Description

disable

Disable NAT traversal.

enable

Enable NAT traversal.

psksecret

Pre-shared secret for PSK authentication. Auto-generated if not specified

password-3

Not Specified

remote-cidr

Remote subnet address and subnet mask.

ipv4-classnet

Not Specified

0.0.0.0 0.0.0.0

remote-type

Type of remote device.

option

-

vgw

Option

Description

vgw

Virtual private gateway.

tgw

Transit gateway.

routing-type

Type of routing.

option

-

dynamic

Option

Description

static

Static routing.

dynamic

Dynamic routing.

sdn

SDN connector name.

string

Maximum length: 35

status

SDN VPN status. Read-only.

integer

Minimum value: 0 Maximum value: 255

0

subnet-id

AWS subnet id for TGW route propagation.

string

Maximum length: 63

tgw-id

Transit gateway id.

string

Maximum length: 63

tunnel-interface

Tunnel interface with public IP.

string

Maximum length: 15

type

SDN VPN type. Read-only.

integer

Minimum value: 0 Maximum value: 65535

0

vgw-id

Virtual private gateway id.

string

Maximum length: 63