Configuring SDN connector
You are required to configure the SDN Connectors if FortiWeb-VMs are in HA Active-Passive mode. This is to notify the load balancer to distribute the traffic to the new master node when fail-over occurs.
Configuring SDN Connectors
- Go to Security Fabric > External Connectors.
- Click Create New.
- Under Public SDN, select Oracle Cloud Infrastructure (OCI). The OCI screen is displayed.
- Configure the settings.
- For Commercial regions, please find the Region Identifier on this page:
https://docs.cloud.oracle.com/en-us/iaas/Content/General/Concepts/regions.htm - For Government regions, please find the Region Identifier on the following pages:
- Log in to OCI.
- Go to Governance and Administration > Identity > User.
- Click the user you want to use.
- Copy the OCID of this user.
- Log in to OCI.
- Go to Governance and Administration > Administration > Tenancy Details.
- Click the Tenancy you want to use.
- Copy the OCID of this Tenancy.
- Log in to OCI.
- Go to Governance and Administration > Identity > Compartments.
- Click the compartment that your load balancer is located in.
- Copy the OCID of this Tenancy.
Name | Enter a name for the SDN Connector. |
Status |
Toggle on to enable the external connector object. Toggle off to disable the external connector object. |
Update Interval (s) |
Specify the update interval for the connector to get OCI objects. |
OCI Server Region Type |
If your OCI server region is either “US Federal Cloud with DISA Impact Level 5 Authorization Regions” or “US Government Cloud with FedRAMP Authorization Regions”, please select Government. Otherwise please select Commercial. |
OCI Server Region |
Enter the Region Identifier of your load balancer. |
User OCID |
To get the User OCID: |
Tenant OCID |
To get the tenant OCID: |
Compartment OCID |
To get the compartment OCID: Note: If you don't have a compartment, you can leave this option empty. |
Certificate | FortiWeb by default uses the rootCA certificate for authentication with OCI. It's the certificate in System > Admin > Certificates > Admin Cert Local. |
Using SDN connector to obtain the HA member information
- Go to System > High Availability > Settings, select Active- Passive Mode.
- Refer to Configuring High Availability (HA) basic settings for the HA basic settings such as Group ID.
- Select the SDN Connector you have created.
- Enter the Load Balancer's OCID in LB OCID.
To get the Load Balancer OCID:
- Log in to OCI.
- Go to Core Infrastructure > Networking > Load Balancers.
- Click the load balancer used for the HA cluster.
- Copy the OCID of this load balancer.
- The HA members whose traffic is distributed by this load balancer will be listed in the table