Fortinet Fortigate - Specifications
Fortinet Fortigate
This page documents the customer-facing specifications for the Fortinet Fortigate virtual firewall deployed from the Evolution Platform catalog.
Quick facts
- Vendor: Fortinet
- Product: Fortinet Fortigate
- Function: Virtual firewall for customer deployments
- Supported deployment modes: single and dual
Interfaces & routing
The diagram above shows a single Fortigate virtual device, an Internet-facing interface that can receive platform-allocated public IPs (with optional extra addresses), and an MPLS-VPN interface that uses VLAN sub-interfaces (IDs 101–148) to host VPN entries. VLANs are summarised in the diagram for readability; platform-allocated public IPs and per-VLAN VPN settings are handled during provisioning.
Common interface behaviour
- Public IP addresses shown for the Internet interface are platform outputs. The platform allocates the primary public IP automatically and displays allocated addresses in deployment outputs.
- VLAN sub-interfaces are configured as part of the MPLS-VPN interface. Each VLAN entry contains a VPN list and optional routing settings such as BGP.
#1 - Internet Interface
- Role: Internet-facing interface for the Fortigate VM.
- Public IPs: The platform assigns the primary Public IP address (platform-allocated). You may request additional addresses by setting Added IP address number.
- How to request extras: Added IP address number accepts an integer 1..8. The platform will allocate the requested extra addresses and include them in the deployment outputs.
#2 - MPLS-VPN interface
- Role: Carrier VPN connectivity via VLAN sub-interfaces.
- VLAN range: VLAN sub-interfaces 101–148. VLANs are presented as a range; select the VLAN IDs you require during creation.
- VPN list per VLAN: For each VLAN you can add a VPN list (minimum 1, maximum 99 items). Each VPN entry includes:
- VPN Name (alphanumeric and -/_ allowed)
- VPN role (one of: any-to-any, client, server)
- BGP per VLAN: Enable BGP is an optional, per-VLAN boolean (default false). When enabled, provide routing information as required.
- AS prepend: AS prepend is an optional integer 1..6 available per VLAN. It is intended to influence AS path advertisement when BGP is used.
The BGP setting is an optional and updatable configuration available on the relevant VLAN sub-interface. When it is not enabled, no BGP-specific configuration is applied through this setting.
Virtual device parameters
- Equipment name (VM hostname): Required. Provide a hostname matching pattern [a-zA-Z0-9-]*, maximum length 22 characters. This is used as the VM hostname in the platform.
- Software image: Required. Select a Fortigate image from the Software list below. Supported images are rendered from the canonical software JSON import.
- VM flavor (size): Required. Choose a flavor from the Flavors list below (for example std1.c1, std1.c2, std1.c4, std1.c8, and DPDK variants). Flavors define vCPU, RAM and disk sizing.
| Standard | DPDK | |
|---|---|---|
| Extra-Small | 1 vCPU 2 GB Mem 64 GB Disk | - |
| Small | 2 vCPU 4 GB Mem 64 GB Disk | 2 vCPU 4 GB Mem 64 GB Disk |
| Medium | 4 vCPU 8 GB Mem 64 GB Disk | 4 vCPU 8 GB Mem 64 GB Disk |
| Medium | 4 vCPU 16 GB Mem 64 GB Disk | 4 vCPU 16 GB Mem 64 GB Disk |
| Large | 8 vCPU 16 GB Mem 64 GB Disk | 8 vCPU 16 GB Mem 64 GB Disk |
Service specific parameters
Service-specific parameters are values you provide at service creation. They are not VM-level or interface IP addresses; they are used by the platform to configure the Fortigate instance during provisioning.
-
Admin password (required)
- General meaning: Administrator password for the device admin account.
- For this VNF: The value is applied during initial provisioning (cloud-init) to set the Fortigate admin password.
- Provided by: customer. Mandatory at creation, not shown in clear in the portal and not updatable after provisioning.
- Constraints: string up to 50 characters.
- Customer action: Provide a strong password when creating the service.
-
Fortinet manager IP address (optional)
- General meaning: IP address of a FortiManager management instance.
- For this VNF: If provided, the platform configures the Fortigate to point to the FortiManager during provisioning.
- Provided by: customer. Optional, not updatable.
- Constraints: valid IPv4 address format.
- Customer action: Provide only when device registration with FortiManager is required.
-
Fortinet manager serial number (optional)
- General meaning: Serial identifier of the FortiManager instance for registration.
- For this VNF: Used alongside the FortiManager IP to register the device with central management if configured.
- Provided by: customer. Optional, not updatable.
- Constraints: alphanumeric and hyphen pattern.
Platform-generated outputs
- Public IP address (platform-allocated): The platform provides the assigned public IPv4 address(es) for the Internet interface and displays them in deployment outputs after provisioning. These are platform outputs, not customer-provided inputs.
Software device versions
Below the available software images are rendered from the canonical software JSON import.
- 7.2.5
- 7.4.9
Licence
Only Bring Your Own Licence (BYOL) type is supported for Fortinet SDWAN. You need to purchase your software licence with Fortinet sales.
Security group
No default security group configured for Fortinet VNE model.