Site-2-Cloud connectivity with FortiGate and Aviatrix

The diagram below shows the environment I’m going to test: Active-Standby This option supports connecting AVX transit gateways to on-prem with only one active tunnel and the other one as backup. The use case is a deployment scenario where on-prem device such as firewall does not support asymmetric routing on two tunnels. Aviatrix configuration: The active/standby configuration will produce the following configuration: FortiGate config To align the FortiGate configuration to the AVX gateways, we need to use BGP Weight attribute to prefer a route received from the AVX primary transit gateway GRE tunnel over the AVX transit gateway ha GRE … Continue reading Site-2-Cloud connectivity with FortiGate and Aviatrix

FortiNet SD-WAN Integration with Aviatrix

BGP to LAN allows an Aviatrix multi-cloud network to communicate with network virtualization appliances (NVAs) without running tunneling protocols. One case is to interoperate with third-party SD-WAN appliances. https://community.aviatrix.com/t/h7htvvc/need-of-conventional-bgp-support-in-the-cloud Constraints LAN interfaces for Aviatrix Transit Primary and third-party cloud instance must be in the different VNets One BGP over LAN connection per gateway is supported. Aviatrix software version 6.8 will not require a dedicated vnet for sd-wan appliances Configuration Once the vnet is created, using the Native Peering, I’ll peer the new vnet with the transit vnet for control and data plane reachability: When the peering is established we can … Continue reading FortiNet SD-WAN Integration with Aviatrix

Deploying an Aviatrix FireNet on Azure with Fortinet FortiGate

Aviatrix Transit FireNet allows the deployment of 3rd party firewalls onto the Aviatrix transit architecture. Transit FireNet works the same way as the Firewall Network where traffic in and out of the specified Spoke is forwarded to the firewall instances for inspection or policy application. FireNet Design The diagram below shows the Aviatrix Firenet design for Azure. When a transit gateway is deployed with the firenet option checked, the Aviatrix controller will: create subnets create UDRs create an internal NLB configure the internal NLB (front end, back-end, healtch check) Aviatrix deploys and configures the Internal Load Balancers for a Firenet. … Continue reading Deploying an Aviatrix FireNet on Azure with Fortinet FortiGate