The following scenario examples are available:
-
Distributed inter-subnet east-west traffic in one AZ Example
-
Distributed inter-subnet east-west traffic between AZ Example
-
Centralized ingress: inspection before load balancer Example
FortiGate CNF delivers an easy-to-deploy, advanced cloud-native firewall service that secures cloud network traffic, while eliminating the need for network redesigns and maintenance. Learn more about cloud-native firewall concepts and how it works. Powered by FortiOS and FortiGuard Labs threat intelligence, FortiGate CNF protects from malware, data breaches and botnets by blocking risky traffic connections, and enforces compliance with geo-specific policies, blocking traffic to/from specified countries.
This 7-minute video walks you through the registration and initial configuration of FortiGate CNF from AWS Marketplace. Visit the FortiGate CNF AWS Marketplace listing to start a free 30-day trial. Learn more about the free trial details here.
You can also review the Getting Started sections in the FortiGate CNF Administration Guide for more information:
Listed below are typical deployment scenarios with instructions on routing traffic to the FortiGate CNF instance. Follow the scenario that matches your architecture, or use the principles presented as a basis for a customized approach.
The following scenario examples are available:
Distributed inter-subnet east-west traffic in one AZ Example
Distributed inter-subnet east-west traffic between AZ Example
Centralized ingress: inspection before load balancer Example
When you first log in to FortiGate CNF, you are presented with the onboarding wizard, which walks you through the process of adding an AWS account.
To add a new cloud account:
You can use the AWS Firewall Manager to create and deploy FortiGate CNF instances.
View step-by-step instructions here.
FortiManager can be used to install and monitor security features on FortiGate CNF instances. After you have added a FortiGate CNF instance to FortiManager, you can view the dashboard, create and install policies, and manage certificates from FortiManager.
To learn more, view the following resources:
Per AWS Marketplace requirements, free trials will not automatically move into pay-as-you-go billing. Accordingly, the process involves backing up and restoring your existing FortiGate CNF instance configuration when switching from a free trial to a paid subscription. The process is as follows:
Welcome to your new Fortinet Community!
You'll find your previous forum posts under "Forums"
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.