Creating VMware NSX fabric connectors
With FortiManager, you can create a fabric connector for VMware NSX, and then import address names from VMware NSX to automatically create dynamic objects that you can use in policies. When you install the policies to one or more FortiGate units, FortiGate uses the information to communicate with VMware NSX and dynamically populate the objects with IP addresses.
When you create a fabric connector for VMware NSX, you are specifying how FortiGate can communicate directly with VMware NSX.
If ADOMs are enabled, you can create one fabric connector per ADOM.
Requirements:
- FortiGate unit or FortiGate VMX Service Manager is managed by FortiManager.
- The managed FortiGate or FortiGate VMX Service Manager is configured to work with VMware NSX .
- IPv4 virtual wire pair policy
FortiGate or FortiGate VMX Service Manager requires the use of an IPv4 virtual wire pair policy.
To create a fabric connector object for NSX:
- Go to Fabric View > External Connectors, and click Create New. The Create New Fabric Connector wizard is displayed.
- Under Private SDN, select VMware NSX-V. The VMware NSX-V screen is displayed.
- Configure the following options, and then click OK:
Type
Displays VMware NSX.
Name
Type a name for the fabric connector object.
Status
Toggle On to enable the fabric connector object. Toggle OFF to disable the fabric connector object.
Update Interval (s)
Specify how often in seconds that the dynamic firewall objects should be updated.
Server
Type the IP address for VMware NSX.
Username
Type the username for VMware NSX.
Password
Type the password for VMware NSX.
VMX
The VMX options identify settings used by the FortiGate VMX Service Manager to communicate with the REST API for NSX Manager.
Service Name
Type the name of the FortiGate VMX service defined on NSX Manager.
Image Location
Type the location of the FortiGate VMX deployment template used by NSX Manager to deploy the FortiGate VMX service.
REST API
The REST API options specify how the FortiGate VMX Service Manager communicates with the REST API for NSX Manager.
Port
Type the port used by the FortiGate VMX Service Manager to communicate with NSX Manager.
Interface
Select the interface used by the FortiGate VMX Service Manager to communicate with NSX Manager. Choose between MGMT and Sync.
Password
Type the password that FortiGate VMX Service Manager uses with the REST API to communicate with NSX Manager.
Note: This is not the admin password for FortiGate VMX Service Manager.
- Click OK to save the connector.
To complete the fabric connector setup:
- Import address names or manually create the dynamic firewall address for the SDN connector. See Importing address names to fabric connectors and Configuring dynamic firewall addresses for fabric connectors.
- Create a virtual wire pair. See Creating virtual wire pairs.
- In the policy package in which you will be creating the new policy, create a firewall policy and include the dynamic firewall address objects for the SDN connector. See Create a new firewall policy.
- Install the policy package to FortiGate. See Install a policy package.
FortiGate communicates with the SDN to dynamically populate the firewall address objects with IP addresses.