Configuring a root FortiGate using the Fabric Overlay Orchestrator
These steps describe how to run the Fabric Overlay Orchestrator on the root FortiGate.
To configure a root FortiGate using the Fabric Overlay Orchestrator:
- Go to VPN > Fabric Overlay Orchestrator.
- Set Status to Enabled. The Role is automatically selected depending on the FortiGate device’s role in the Fortinet Security Fabric. When configuring the root FortiGate, confirm the Role is Hub. The Fabric root must always be the hub. For Policy Creation, select Automatic. Click Next.
- For Overlay, select one or more interfaces as the Incoming interface or the underlay link over which the VPN overlay will be built, configure the Pre-shared key, and click Next. The example selects two incoming interfaces:
- For Local Network, configure routing and local subnets to share with the VPN network, namely, the BGP AS, loopback address block, and shared interfaces settings:
Option
Description
BGP AS
Optionally, you can configure the BGP AS number.
By default, this setting is set to 65400.
Loopback address block
Optionally, you can configure the loopback IP address.
By default, this setting is set to 10.20.1.1/255.255.255.0.
Shared interfaces
Select the interface of the local network to share with the VPN network
Click Next.
- For the first Summary step, review the configured settings and click Apply.
- For the second Summary step, observe that the following settings have been created as follows:
Option
Description
SD-WAN Zone
Status > SD-WAN zone. In the example, this is fabric_vpn_sdwan.
VPN Tunnels
Overlay > Incoming interface > Phase 1 Interface. In the example, they are fabric_vpn1 and fabric_vpn2.
BGP
Local Network > BGP AS, Local Network > Shared subnets. In the example, the BGP AS is 65400 and subnets are 10.20.1.1/32 and 172.16.1.0/30.
Loopback Interface
Local Network > Loopback interface. In the example, it is F_Hub_loop.
Firewall Policies
Overlay > Incoming interface > Policy, Local Network > Shared subnets > Policies. In the example, they are Overlay: Fabric_overlay_0, Fabric_overlay_1, Shared subnets: fabric_vpn_1_in, fabric_vpn_0_out, fabric_vpn_0_in.