Hi!
I think I'm confortable with Azure networking, I'm ok with networking in general. Yet I never used SDWAN feature on Fortigate.
I'm looking into the option to put a single Fortigate VM into Azure in a hub&spoke model and use SDWAN feature. I don't really see a need for Azure virtual WAN as per the size of the limited deployment, and the cost of Az vWAN can't be justified. I would appreciate some guidance please.
1/ Is it possible to have Express Route and Internet as the underlay networks? Any limitation?
2/ Is it possible to have Express Route reachable on internal/LAN side in such a SDWAN setup? Or does Fortigate SDWAN zone setup require a dedicated NIC for WAN port?
3/ Any Fortinet document you would recommend please? Googling Fortigate SDWAN and Azure always returns content related to vWAN deployement model.
Thanks!
1. In a hub-and-spoke model using FortiGate VM in Azure with SD-WAN feature, it is possible to have ExpressRoute and internet as the underlay networks without limitations. You can configure SD-WAN rules to route traffic based on your requirements.
2. In this setup, you can have ExpressRoute reachable on the internal/LAN side. FortiGate SD-WAN zone setup does not necessarily require a dedicated NIC for the WAN port. You can configure the interfaces accordingly within the FortiGate VM.
3. For Fortinet documentation on configuring FortiGate SD-WAN in Azure without using Azure Virtual WAN, I recommend checking the Fortinet Document Library at https://docs.fortinet.com/4d-resources/SD-WAN. You may find detailed deployment guides and best practices for setting up SD-WAN on FortiGate VM in Azure.
User | Count |
---|---|
2403 | |
1296 | |
778 | |
541 | |
454 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.