Fortinet black logo

SDN connector integration with AWS

Copy Link
Copy Doc ID 22bbe74d-88e9-11eb-9995-00505692583a:486923
Download PDF

SDN connector integration with AWS

You can use FortiManager to create SDN connectors for AWS and install the SDN connectors to FortiOS.

The SDN connectors in FortiManager define the connector type and include information for FortiOS to communicate with and authenticate with the products. In some cases the FortiGate must communicate with products through the SDN connector, and in other cases the FortiGate communicates directly with the products.

FortiOS works without the SDN connector to communicate directly with AWS.

Following is an overview of creating SDN connectors for AWS using FortiManager:

  1. Create an SDN connector object for AWS. See Creating Fabric connector objects for AWS.
  2. Import address names from AWS to the SDN connector object. See Importing address names to fabric connectors.

    The address names are imported and converted to firewall address objects. The objects do not yet include IP addresses. The objects display on the Firewall Objects > Addresses pane.

  3. In the policy package in which you will be creating the new policy, create an IPv4 policy and include the firewall address objects for AWS. See Creating an IP address policy.
  4. Install the policy package to FortiGate. See Installing a policy package.

    FortiGate communicates with AWS to dynamically populate the firewall address objects with IP addresses.

If the filter names change in AWS after you import them to FortiManager, you must modify the filter again.

SDN connector integration with AWS

You can use FortiManager to create SDN connectors for AWS and install the SDN connectors to FortiOS.

The SDN connectors in FortiManager define the connector type and include information for FortiOS to communicate with and authenticate with the products. In some cases the FortiGate must communicate with products through the SDN connector, and in other cases the FortiGate communicates directly with the products.

FortiOS works without the SDN connector to communicate directly with AWS.

Following is an overview of creating SDN connectors for AWS using FortiManager:

  1. Create an SDN connector object for AWS. See Creating Fabric connector objects for AWS.
  2. Import address names from AWS to the SDN connector object. See Importing address names to fabric connectors.

    The address names are imported and converted to firewall address objects. The objects do not yet include IP addresses. The objects display on the Firewall Objects > Addresses pane.

  3. In the policy package in which you will be creating the new policy, create an IPv4 policy and include the firewall address objects for AWS. See Creating an IP address policy.
  4. Install the policy package to FortiGate. See Installing a policy package.

    FortiGate communicates with AWS to dynamically populate the firewall address objects with IP addresses.

If the filter names change in AWS after you import them to FortiManager, you must modify the filter again.