Microsoft Azure, Fortinet Active-Passive Firewall, How to Deploy Step By Step

  Рет қаралды 14,231

Network Experts

Network Experts

4 жыл бұрын

Microsoft Azure, Fortinet Active-Passive Firewall, How to Deploy Step By Step
ARM Template Link
github.com/jvhoof/fortinet-az...
github.com/fortinetsolutions/...

Пікірлер: 27
@johnt3933
@johnt3933 3 жыл бұрын
Amazing, well done putting this together!
@MrArsalan1988
@MrArsalan1988 3 жыл бұрын
very helpful
@ee07168
@ee07168 3 жыл бұрын
Thanks
@EyeIn_The_Sky
@EyeIn_The_Sky 2 жыл бұрын
How about the UDR setup that needs to be done to forward traffic from all protected subnets to the FW and out to the internet? It is difficult to do as there are load balancers involved both internal and external...
@UnitGFC
@UnitGFC 3 жыл бұрын
Do you recommend this deployment model or HA (active/passive) using the SDN connector and without any Azure LB? Can you also give the reasons for your preferred choice?
@ee07168
@ee07168 3 жыл бұрын
I would highly recommend to go with Load Balancer.
@josearmandotorres3118
@josearmandotorres3118 2 жыл бұрын
I have a issue, with my Fortigates deploy with SDN connector, when I want to do a HA test, reboot the master firewall an them look the traffic in the slave firewall but the Azure UDRs routing tables don't update, in the SDN connector each firewall is well configured. Can you help me?
@mdabdulmoiz
@mdabdulmoiz 3 жыл бұрын
2:05 what is protected subnet its not clear, we can have VM on internal subnet right? then whats the point of protected subnet? 172.16.137.0/24 is protected subnet what will be default gateway for VM under this? how traffic from outside world reach protected subnet? can anyone please mention the concept of protected subnet, when I deployed FGT in azure as a single VM i had only external and internal subnet , VM's on internal subnet and Route table for internal subnet to go out.
@hello_i_am_rogue
@hello_i_am_rogue 3 жыл бұрын
How does this handle IPsec tunnels, would they failover?
@ee07168
@ee07168 3 жыл бұрын
In front of fortigate there is Ext LB which is sending a Health probe. Only active firewall always send a probe response.
@patrickverora
@patrickverora 2 жыл бұрын
We have deployed Active passive using loadbalancer but when failover occur ip address of firewall don't switch and now VIP as well as static routes are getting sync . We are not able to access SSL VPN and IpSec tunnel due to this . Anyone has deployed it
@Rahimbhamani
@Rahimbhamani 4 жыл бұрын
Please also share how UDR will be configured so that all the internet based traffic route towards Fortinet firewall. Also test HA. Secondly, if we want fortinet firewall as a gateway to both internal subnet
@ee07168
@ee07168 4 жыл бұрын
Hi thanks for the your acknowledgement i will share new video for fortigate api deployment and i will show the UDR as well
@ee07168
@ee07168 4 жыл бұрын
For UDR please watch this video as well it will help you kzbin.info/www/bejne/Zn_Pmn6Lp7yUr6c
@muhammadattaullah6236
@muhammadattaullah6236 3 жыл бұрын
@@ee07168 Dear Sajid I tried to send you an email to your mention Yahoo account but it's not working can you please send me an email on atta_fsd@hotmail.com, I want to talk with you.
@muhammadattaullah6236
@muhammadattaullah6236 3 жыл бұрын
Dear Sajid, Can you please take a look and let me know if possible for you. Thanks.
@Brahman00007
@Brahman00007 3 жыл бұрын
how to get license? plz guide. license for training purpose.
@sufyanahmed705
@sufyanahmed705 4 жыл бұрын
i am looking for a video related to azure firewall, can you kindly explain that as well
@ee07168
@ee07168 4 жыл бұрын
will try to add IA
@dancorain4860
@dancorain4860 3 жыл бұрын
How can I make a VPN connection using the Public Load Balancers? Azure LB doesn't support ESP packets.
@ee07168
@ee07168 3 жыл бұрын
if your remote devices NAT traversal you can use it :)
@dancorain4860
@dancorain4860 3 жыл бұрын
@@ee07168 thank you so much . You were right . But also DSR needs to be enabled on the public AZ LB side . Thanks
@ee07168
@ee07168 3 жыл бұрын
@@dancorain4860 welcome Dear Dan
@zaid8627
@zaid8627 3 жыл бұрын
i deployed standalone fortigate on azure everthing was fine i could login to fortigate gave BYOL license, did some setting on firewall and under interfaces wan side interface was set as dhcp i changed it to static and lost connectivity for both GUI and CLI is there a way i could change back from azure portal and get back the connectivity?
@ee07168
@ee07168 3 жыл бұрын
in azure there is an option serial connect connect through it
@zaid8627
@zaid8627 3 жыл бұрын
@@ee07168 thanks
@mdabdulmoiz
@mdabdulmoiz 3 жыл бұрын
@@ee07168 wow thanks i never thought of this.
Was ist im Eis versteckt? 🧊 Coole Winter-Gadgets von Amazon
00:37
SMOL German
Рет қаралды 37 МЛН
Я нашел кто меня пранкует!
00:51
Аришнев
Рет қаралды 4,4 МЛН
Final muy increíble 😱
00:46
Juan De Dios Pantoja 2
Рет қаралды 54 МЛН
KINDNESS ALWAYS COME BACK
00:59
dednahype
Рет қаралды 138 МЛН
Azure Load Balancer Deep Dive
49:28
John Savill's Technical Training
Рет қаралды 63 М.
Azure Networking, User Defined Routes, and Network Virtual Appliances
21:24
Palo Alto  VM-Series on Azure
13:01
Network Experts
Рет қаралды 14 М.
Microsoft Azure Gateway Load Balancer Deep Dive
32:16
John Savill's Technical Training
Рет қаралды 16 М.
Getting Started with Public Load Balancers in Azure
16:57
Travis Roberts
Рет қаралды 6 М.
Was ist im Eis versteckt? 🧊 Coole Winter-Gadgets von Amazon
00:37
SMOL German
Рет қаралды 37 МЛН