FortiGate VM Deployment example – KVM

Deployment example – KVM

Once you have downloaded the FORTINET.out.kvm.zip file and extracted virtual hard drive image file fortios.qcow2, you can create the virtual machine in your KVM environment.

The following topics are included in this section:

Create the FortiGate VM virtual machine

Configure FortiGate VM hardware settings

Start the FortiGate VM

Create the FortiGate VM virtual machine

To create the FortiGate VM virtual machine:

  1. Launch Virtual Machine Manager (virt-manager) on your KVM host server.

The Virtual Machine Manager home page opens.

  1. In the toolbar, select Create a new virtual machine.
  2. Enter a Name for the VM, FGT-VM for example.
  3. Ensure that Connection is localhost. (This is the default.)
  4. Select Import existing disk image.

KVM                                                                       Create the FortiGate VM virtual machine

  1. Forward.
  2. In OS Type select Linux.
  3. In Version, select a Generic version with virtio.

Configure                       hardware settings                                                                    Deployment example – KVM

  1. Select Browse.
  2. If you copied the fortios.qcow2 file to /var/lib/libvirt/images, it will be visible on the right. If you saved it somewhere else on your server, select Browse Local and find it.
  3. Choose Choose Volume.
  4. Select Forward.
  5. Specify the amount of memory and number of CPUs to allocate to this virtual machine. The amounts must not exceed your license limits. See FortiGate VM Overview on page 10.
  6. Select Forward.
  7. Expand Advanced options. A new virtual machine includes one network adapter by default. Select a network adapter on the host computer. Optionally, set a specific MAC address for the virtual network interface. Set Virt Type to virtio and Architecture to qcow2.
  8. Select Finish.

Configure FortiGate VM hardware settings

Before powering on your FortiGate VM you must add the log disk and configure the virtual hardware of your FortiGate VM.

To configure settings for FortiGate VM on the server:

  1. In the Virtual Machine Manager, locate the name of the virtual machine and then select Open from the toolbar.
  2. Select Add Hardware. In the Add Hardware window select Storage.

KVM                                                                                                Start the FortiGate VM

  1. Create a disk image on the computer’s harddrive and set the size to 30GB.
  2. Enter:
Device type Virtio disk
Cache mode Default
Storage format raw
  1. Select Network to configure add more the network interfaces. The Device type must be Virtio.

A new virtual machine includes one network adapter by default. You can add more through the Add Hardware window. FortiGate VM requires four network adapters. You can configure network adapters to connect to a virtual switch or to network adapters on the host computer.

  1. Select Finish.

Start the FortiGate VM

You can now proceed to power on your FortiGate VM. Select the name of the FortiGate VM in the list of virtual machines. In the toolbar, select Console and then select Start.

 


Having trouble configuring your Fortinet hardware or have some questions you need answered? Check Out The Fortinet Guru Youtube Channel! Want someone else to deal with it for you? Get some consulting from Fortinet GURU!

This entry was posted in Administration Guides, FortiGate on by .

About Mike

Michael Pruett, CISSP has a wide range of cyber-security and network engineering expertise. The plethora of vendors that resell hardware but have zero engineering knowledge resulting in the wrong hardware or configuration being deployed is a major pet peeve of Michael's. This site was started in an effort to spread information while providing the option of quality consulting services at a much lower price than Fortinet Professional Services. Owns PacketLlama.Com (Fortinet Hardware Sales) and Office Of The CISO, LLC (Cybersecurity consulting firm).

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.