Skip to main content

Fortinet SD-WAN - Specifications

Fortinet SD-WAN Gateway

This page documents the Fortinet Fortigate SD‑WAN Gateway available on the Evolution Platform. It describes supported deployment modes, available images and flavors, interfaces (including VLAN sub‑interfaces), routing options and the service parameters required during provisioning.

Flavors

Select a VM size from the available flavor list. DPDK family flavors map to DPDK-capable images when you choose a DPDK image variant.

Flavors for Fortinet Fortigate
StandardDPDK
Extra-Small
1 vCPU
2 GB Mem
64 GB Disk
-
Small
2 vCPU
4 GB Mem
64 GB Disk
2 vCPU
4 GB Mem
64 GB Disk
Medium
4 vCPU
8 GB Mem
64 GB Disk
4 vCPU
8 GB Mem
64 GB Disk
Medium
4 vCPU
16 GB Mem
64 GB Disk
4 vCPU
16 GB Mem
64 GB Disk
Large
8 vCPU
16 GB Mem
64 GB Disk
8 vCPU
16 GB Mem
64 GB Disk

Software device versions

Supported software image versions are rendered from the platform component data below.

  • 7.2.5

Interfaces

The diagram above shows the Fortinet Fortigate VM with its Internet-facing interface (platform-allocated public IPs) and the MPLS‑VPN interface that hosts VLAN sub‑interfaces. VLAN sub‑interfaces are grouped in the diagram for readability — their full list and parameters are documented below.

Common interface notes:

  • Public IP addresses shown for the Internet interface are platform-generated outputs and are displayed after allocation (informational).
  • VLAN sub‑interfaces are configured on the MPLS interface and each VLAN can host one or more VPN entries and optional per‑VLAN routing settings.

#1 - Internet Interface (optional)

Role: Internet-facing WAN interface. The platform allocates a primary public IP. Customers may request additional public IPs using the Added IP address number parameter.

  • Added IP address numberOptional, updatable. Integer between 1 and 8. Request how many extra public IP addresses you want allocated in addition to the primary public IP.
  • Public IP address (primary)Informational (platform output). Primary IPv4 address allocated and displayed by the platform after provisioning.

#2 - MPLS-VPN interface (optional)

Role: Connects to Orange MPLS‑VPN using VLAN child interfaces. Supported VLAN range: 101–148.

Per VLAN sub-interface (101–148) you may configure:

  • VPN list — one or more VPN entries (min 1, max 99). Each entry contains:
    • VPN Name — alphanumeric identifier (pattern: letters, digits, hyphen, underscore).
    • VPN role — one of any-to-any, client, server.
  • BGP settings (optional, per VLAN):
    • Enable BGPOptional and updatable. Boolean (default: false). When false, BGP neighbor configuration for the VLAN remains inactive.
    • AS prependOptional and updatable. Integer 1..6. The internal specification notes AS prepend is intended for backup VM usage in some topologies; the parameter is available but the specification does not define automatic failover behaviour.

When many VLANs share the same configuration pattern, provide the VPN list and BGP settings per VLAN in the console rather than repeating identical entries across multiple VLANs.

Routing (BGP)

  • BGP is optional and configurable per VLAN on the MPLS interface. When Enable BGP is false, no active BGP sessions are established for that VLAN by platform provisioning.
  • AS prepend applies per VLAN when BGP is used; allowed values 1..6.
  • VM AS number is a VM-level setting used as the local AS for BGP sessions; it is configured during provisioning and is not updatable after creation.

Virtual device parameters

Provide VM-specific values during creation:

  • VM nameRequired. Hostname up to 22 characters (letters, digits, hyphen).
  • Software imageRequired. Choose one of the supported Fortigate images displayed in the Software device versions list.
  • VM flavorRequired. Select the VM flavor (standard or DPDK families) from the Flavors table.
  • VM AS numberOptional, not updatable. Integer range 1..4294967295 (2- or 4-byte AS allowed).

Service parameters

Service-specific parameters are values provided at service level (during provisioning) that are not per-interface addresses or platform outputs.

  • PasswordRequired; not updatable. Administrator password for the Fortigate admin account. Provide a string 1..50 characters; the platform injects this into the cloud-init template to set the device admin password at first boot.
  • Fortinet manager IP addressOptional; not updatable. IPv4 address of your FortiManager instance. If provided together with the FortiManager serial number, cloud-init configures central management on first boot.
  • Fortinet manager serial numberOptional; not updatable. Alphanumeric serial number used to pair the Fortigate with FortiManager when central management is configured.

Platform-generated outputs

  • Public IP address (primary) — Primary public IPv4 address allocated to the Internet interface (informational platform output).
  • Extra Public IP addresses — Additional public IPv4 addresses allocated when the customer requests extra IPs via the Added IP address number parameter (informational platform outputs).

Licence

Only Bring Your Own Licence (BYOL) type is supported for Fortinet SD-WAN. You need to purchase your software licence with Fortinet sales.

Security group

No default security group configured for Fortinet VNE model.