FortiGate Connector for Cisco ACI

Prerequisites

Cisco Side

Before the FortiGate Connector for Cisco ACI can be successfully deployed, a number of prerequisites need to be satisfied within the Cisco environment.

One of the following Cisco ACI environments needs to be in place:

  • Cisco ACI v1.1(2h) l Cisco ACI v1.1(3f)

Within the Cisco ACI, the following configurations need to be completed before Layer 4 -7 Services (in this case, the FortiGate Connector) can be deployed:

  • Creation of Access Policies configuration under Fabric menu l Creation of any need Tenant(s) l Creation of Network(s) (including Bridge Domain) l Creation of Application Profile(s) l Creation of End Point Group(s) l Creation of Contract(s)

For detail, please consult Cisco APIC deployment Guide.

http://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/1-x/L4-L7_Services_ Deployment/guide/b_L4L7_Deploy.html

FortiGate Side

Before the FortiGate Connector for Cisco ACI can be successfully deployed, a number of prerequisites need to be satisfied on the FortiGate side of the equation.

Physical Firewall

  1. Configure administrator user name and password.
  2. Enable http/https on mgmt. port.
  3. Configure IP address in mgmt. port.
  4. Enable VDOM-Admin globally.
  5. Configure Port-Group if needed.

VM Firewall

  1. Assign network ports before start VM
  2. Configure administrator user name and password.
  3. Enable http/https on mgmt. port.
  4. Configure IP address in mgmt. Ports
  5. Enable VDOM-Admin globally

Having trouble configuring your Fortinet hardware or have some questions you need answered? Check Out The Fortinet Guru Youtube Channel! Want someone else to deal with it for you? Get some consulting from Fortinet GURU!

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.