We've have a pair of FortiGates in Azure in HA and we're setting up the SDN Connector using Managed Identity. We do not understand what the resources path setting is doing for us. From what I read it seems that this setting restricts the scope of what the connector will interact with in Azure. However, we are defining all the route tables in Azure that we want the connector to update in the event of a failover. I don't believe we need the resource path settings (subscription id, and resource group). I don't believe they will do anything for us in our configuration. Can someone let me know if I am right? I want to leave that setting turned off entirely.
Hello Phenster44,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Hello,
We are still looking for an answer to your question.
We will come back to you ASAP.
Hello Phenster44,
I found this solution. Can you tell us if it helps, please?
In the context of setting up the SDN connector using Managed Identity for FortiGate in Azure, the "resources path" setting, which includes the Subscription ID and Resource Group, is crucial for defining the scope of resources that the connector can interact with. Here's why it is important:
Scope Definition: The resources path setting restricts the scope of what the connector can interact with in Azure. It ensures that the connector only has access to the specific resources it needs to manage, such as network interfaces and route tables.
Security and Permissions: By specifying the Subscription ID and Resource Group, you ensure that the connector has the necessary permissions to make changes only within the defined scope. This is important for security and to prevent unauthorized access to other resources.
Failover Management: During a failover, the SDN connector needs to update route tables and public IP associations. The resources path setting ensures that these updates are applied to the correct resources within the specified subscription and resource group.
If you do not configure the resource path settings, the connector may not function as expected, as it might not have the necessary permissions or scope to manage the required resources during a failover. Therefore, it is recommended to configure these settings to ensure proper operation of the SDN connector in your HA setup.
| User | Count |
|---|---|
| 2806 | |
| 1426 | |
| 812 | |
| 758 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.