Hi!
I'm setting up a replacement for a Hub and Spoke with a Fortigate ranging from 40F-100F
I thought about using Provisioning Templates to basically use ZTP and Authorize those devices and then aplplying IPSEC Templates (Hub and Spoke) to setup a tunnel from the get go.
I see quite a few people with that kind of Setup, but they are all talking about per device mappings to normalized Interfaces and then using Meta Field Variables for the local subnets. This is fine, but then first need to add the Fortigate and then add it to the 'per device mapping' I haven't tried that yet, but that seems like a more non-ztp'ish way of doing stuff.
We'll deploy mainly 2 Types of Policy-Packages to those Devices (Spoke-A and Spoke-b) Basically due to complexity for some of the branches..
How would you aprouch that kind of a Setup?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
At least as far as normalized interfaces are concerned you could also use per plattform mappings. So you set one mapping for each FGT model you have and when ever you add a FGT of that model to the ADOM it will get that mapping upon deployment.
Addressobjects only need to have a per device mapping if they are device specific. Objects that are the same for all your FGT don't need a mapping at all.
If you have more than one adom you can create addressobjects in global adom and assign them.
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Hi @monro ,
• Some of the methods used to point the FGT to the FMG address are described in the following documents:
• DHCP:
https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/861490/zero-touch-provisioning-with-fort...
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-perform-zero-touch-provisioning-wit...
• FortiDeploy + FMG:
https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/316039/zero-touch-provisioning-with-fort...
• USB drive containing firmware and basic central-management config:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Automatic-installation-of-Firmware-and-sys...
https://community.fortinet.com/t5/FortiManager/Technical-Tip-ZTP-basic-configuration-and-troubleshoo...
https://community.fortinet.com/t5/FortiManager/Technical-Tip-New-Logic-of-SD-WAN-templates-for-FMG-7...
https://docs.fortinet.com/document/fortigate/7.0.0/sd-wan-new-features/794804/new-sd-wan-template-fm...
https://community.fortinet.com/t5/FortiManager/Technical-Tip-New-Meta-Variables-and-their-usage-incl...
Try when you create a model device and after every template is added to Install it and then to connect the real device to the model one.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.