SD-WAN Fortinet Solution Deployment / Configuration Guide
About
This document describes the steps to deploy and configure the Fortinet SD-WAN solution.
Prerequisites
- Fortinet integration in SevOne NMS supports standard basic authentication using the FortiManager URL, username, and password.
- SNMP v2 or SNMP v3 details for the fortigate devices, based on device compatibility.
Device Onboarding
When onboarding Fortinet devices in SevOne NMS, you only need to add a single SD-WAN integration device (the Fortinet Orchestrator) with the appropriate orchestrator credentials. Once the integration device is added and saved, SevOne NMS automatically discovers all FortiGate devices managed by that integration. There is no need to manually add each FortiGate device.
If the FortiGate devices already exist in SevOne NMS with SNMP-only monitoring and valid IP addresses, adding the SD-WAN integration device with both SNMP and SD-WAN plugins will automatically associate the integration with the existing devices. The SD-WAN metadata will then populate alongside the existing SNMP data, without creating duplicates.
To onboard Fortinet devices in SevOne NMS, execute the following steps.
- Using a web browser, navigate to the SevOne NMS appliance URL, log in with your credentials, then go to the Devices menu via the navigation bar, select Device Manager, and click Add Device to create a new device.
- On the New Device page, add the following details.

- In the Name field, enter the device name.
- In the Alternate Name field, enter an alternate device name. You can search for a device by its alternate name.
- In the Description field, enter the device description. You can use this to provide additional information about the function, location, or any other pertinent information about the device.
- In the IP Address field, enter the device IP address.
- By default, the plugin is set to SNMP. Click the plugin drop-down and select SDWAN.
- Select the Enable SDWAN API Integration check box.

- Click the Vendor drop-down and select the FortiManager option.
- In the FortiManager URL field, enter the URL for SDWAN vendor, FortiManager.
- In the Username field, enter the username for SDWAN vendor, FortiManager.
- In the Password field, enter the password for SDWAN vendor, FortiManager.
- Enable the Auto-discover and monitor associated FortiGates - Use SNMP Plugin checkbox to automatically discover and monitor FortiGate devices.
- Select the Enable SDWAN API Integration check box.
- Once the SDWAN plugin is configured, from the plugin drop-down, select SNMP plugin.

- Ensure that the field SNMP Capable check box is selected to enable the discovery of SNMP object types and to poll SNMP data on the device.
- In the Version field and select the version. For example, select 3 from the available options in the drop-down list.
- Enter the Username and Password for FortiGate devices.
Note: Ensure the same SNMP credentials are configured on all FortiGate devices.
- Complete any remaining fields and click Save to save the current changes as a New Device. This device is then queued for discovery.
- Click the Devices menu and select Discovery Manager. Here, you will see that the device is in the discovery queue.
- After the discovery process is completed, FortiGate devices will be visible on the Device Manager screen.

- To retrieve the metadata of a FortiGate object, execute the steps as shown below.
- Choose a device from the list that you wish to view the metadata for.
- Click
in the Actions column to open the Edit Metadata pop-up. - In the Edit Metadata pop-up, locate the section SDWAN_DEVICES to find the metadata fields.

- To retrieve the metadata of a Fortinet FortiGate object, follow these steps.
- From the navigation bar, click the Devices menu and select Object Manager.
- Choose an object from the list of type Virtual WAN Link / Virtual WAN Link (Fortinet FortiGate) or Interface / Interface (Fortinet FortiGate) for which you want to view the metadata.
- Click
in the Actions column to open the Edit Metadata pop-up.

The TopN Report Views are automatically imported and are listed as shown below. Manual importing is not required for these reports.
- FortiGate - Aggregate Links Utilization - In & Out
- FortiGate - CPU Utilization
- FortiGate - Device Reachability
- FortiGate - Disk Utilization
- FortiGate - Highest Interface Errors
- FortiGate - ICMP Response Time
- FortiGate - Memory Utilization
- FortiGate - Most Utilized Interface - In
- FortiGate - Most Utilized Interface - Out
- FortiGate - Most Utilized Interfaces - In & Out
- FortiGate - Packet Loss - ICMP from SevOne
- FortiGate - Performance SLA - Jitter
- FortiGate - Performance SLA - Latency
- FortiGate - Performance SLA - Packet Loss
- FortiGate - Performance SLA - State, Pkt Loss, Jitter, Latency
- FortiGate - Total Errors and Discards
- FortiGate - Tunnel Utilization - In & Out
Fortinet DNC / Flow Specific Changes in SevOne NMS
Flow Interface Manager
To check the flows received on SevOne NMS, from the navigation bar, click the Administration menu, select Flow Configuration, and then select Flow Interface Manager.

Deny 'Router-Generated' on Flow Rules
Fortinet forwards duplicate flow records for the same connection. So, it is necessary to deny flow from the Router Generated interface to avoid double counting. To create a rule, click the Administration menu, select Flow Configuration, and then select Flow Rules.
Please refer to Flow Rules for details.

To configure additional parameters in the SD-WAN Flow Views options template, please refer to SD-WAN Flow Views Additional Configuration Guide
Support Long Flows on SevOne NMS

Solution Verification & Customization
- Enter the URL for the SevOne NMS appliance into your web browser to display the Login page.
- Enter the credentials and click Login. For example, Username: admin and Password: SevOne
- To check MIB files imported, click the Administration menu, select Monitoring Configuration, and then select MIB Manager.
Please refer to MIB Manager for details.

- To check device groups imported, click the Devices menu and select Grouping, then Device Groups.
Please refer to Device Groups for details.

- To check object groups imported, click the Devices menu, select Grouping, and then select Object Groups.
Please refer to Object Groups for details.
Important: You can change the Object Group Membership Rules based on your network environment. - To check object types, click on the Administration menu and select Monitoring Configuration, then Object Types.
Please refer to Object Types for details.

Fortinet OOTB Reports in SevOne Data Insight
- Log in to your SevOne Data Insight by navigating to the appropriate URL in your web browser. Enter your credentials on the login page and click Login.
- Click on the Reports, to view the Report Manager page. Under SevOne Folders, select Fortinet folder from the SD-WAN drop-down list. Select the desired Fortinet Report displayed. You can either click on the Run button as shown here or click on the report link directly to view detailed OOTB reports.
Note: The following reports get imported.- FortiGate Device Summary
- FortiGate Interface Summary
- FortiGate Performance SLA Tests
- FortiGate Tunnel Summary
- Fortinet FortiGate Dashboard
-
Click on Devices to view the Device Manager page, then select the relevant datasource from the Datasource drop-down list to view the corresponding devices and their details.
Example
