FortiManager
FortiManager supports network operations use cases for centralized management, best practices compliance, and workflow automation to provide better protection against breaches.
smkml
Staff
Staff
Article Id 420420
Description

 

This article describes how to import and use each templates (IPsec, BGP, SDWAN) in FortiManager, especially on Hub and Spoke setup on the FortiGate. Sometimes troubleshooting on non-working setup can be challenging, if deployed from FortiManager using templates, for example is SDWAN Overlay. This can reduced the time for troubleshooting on FortiGate and FortiManager, and at the same time achieving the same goal to use a template for a new device moving forwards. 

 

Scope

 

FortiManager.

 

Solution

 

  1. Make sure the configuration for IPsec, BGP and SDWAN are working correctly on FortiGate side.
  2. FortiGate and ADOM version must match. 

 

For example: FortiManager version v7.4.7, ADOM version 7.4, where FortiGate must in v7.4.x.

 

  1. Import each configuration as template on each IPsec, BGP and SDWAN section on Device Manager -> Provisioning Templates.

 

IPsec Template.

Go to Device Manager -> Provisioning Templates -> IPsec Tunnel -> More -> Import.

 

import ipsec-hub config as template.png

 

ipsec-hub template.png

 

import ipsec-spoke config as template.png

 

ipsec-spoke template.png

 

SD-WAN Template:

Device Manager -> Provisioning Templates -> SD-WAN -> More -> Import.

 

import sdwan-hub config as template.png

 

sdwan-hub template.png

 

import sdwan-spoke config as template.png

 

sdwan-spoke template.png

 

BGP Template:

Device Manager -> Provisioning Templates -> BGP -> More -> Import.

 

import bgp-hub config as template.png

 

bgp-hub template.png

 

import bgp-spoke config as template.png

 

bgp-spoke template.png

 

Combined all the templates into Template Groups, and add other templates such as System Templates or the CLI if necessary for the new device deployment installation.

 

template groups.png

 

Related articles:

Troubleshooting Tip: Install error failed due to Provisioning Template (error -999) 

Troubleshooting Tip: IPsec Template install does not show in Install Preview 

Contributors