SD-WAN Fortinet Solution Deployment / Configuration Guide

About

This document describes the steps to deploy and configure the Fortinet SD-WAN solution.

Prerequisites

  • Fortinet integration in SevOne NMS supports standard basic authentication using the FortiManager URL, username, and password.
  • SNMP v2 or SNMP v3 details for the fortigate devices, based on device compatibility.

Device Onboarding

Note:

When onboarding Fortinet devices in SevOne NMS, you only need to add a single SD-WAN integration device (the Fortinet Orchestrator) with the appropriate orchestrator credentials. Once the integration device is added and saved, SevOne NMS automatically discovers all FortiGate devices managed by that integration. There is no need to manually add each FortiGate device.

If the FortiGate devices already exist in SevOne NMS with SNMP-only monitoring and valid IP addresses, adding the SD-WAN integration device with both SNMP and SD-WAN plugins will automatically associate the integration with the existing devices. The SD-WAN metadata will then populate alongside the existing SNMP data, without creating duplicates.

To onboard Fortinet devices in SevOne NMS, execute the following steps.

  1. Using a web browser, navigate to the SevOne NMS appliance URL, log in with your credentials, then go to the Devices menu via the navigation bar, select Device Manager, and click Add Device to create a new device.
  2. On the New Device page, add the following details.

    Fortinet New Device

    1. In the Name field, enter the device name.
    2. In the Alternate Name field, enter an alternate device name. You can search for a device by its alternate name.
    3. In the Description field, enter the device description. You can use this to provide additional information about the function, location, or any other pertinent information about the device.
    4. In the IP Address field, enter the device IP address.
    5. By default, the plugin is set to SNMP. Click the plugin drop-down and select SDWAN.
      1. Select the Enable SDWAN API Integration check box.

        Fortinet SD-WAN Plugin

      2. Click the Vendor drop-down and select the FortiManager option.
      3. In the FortiManager URL field, enter the URL for SDWAN vendor, FortiManager.
      4. In the Username field, enter the username for SDWAN vendor, FortiManager.
      5. In the Password field, enter the password for SDWAN vendor, FortiManager.
      6. Enable the Auto-discover and monitor associated FortiGates - Use SNMP Plugin checkbox to automatically discover and monitor FortiGate devices.
    6. Once the SDWAN plugin is configured, from the plugin drop-down, select SNMP plugin.

      Fortinet SNMP Plugin

    7. Ensure that the field SNMP Capable check box is selected to enable the discovery of SNMP object types and to poll SNMP data on the device.
    8. In the Version field and select the version. For example, select 3 from the available options in the drop-down list.
    9. Enter the Username and Password for FortiGate devices.
      Note: Ensure the same SNMP credentials are configured on all FortiGate devices.
    10. Complete any remaining fields and click Save to save the current changes as a New Device. This device is then queued for discovery.
    11. Click the Devices menu and select Discovery Manager. Here, you will see that the device is in the discovery queue.
    12. After the discovery process is completed, FortiGate devices will be visible on the Device Manager screen.

      Fortinet Devices

    13. To retrieve the metadata of a FortiGate object, execute the steps as shown below.
      1. Choose a device from the list that you wish to view the metadata for.
      2. Click Edit metadata in the Actions column to open the Edit Metadata pop-up.
      3. In the Edit Metadata pop-up, locate the section SDWAN_DEVICES to find the metadata fields.

        Fortinet Metadata

    14. To retrieve the metadata of a Fortinet FortiGate object, follow these steps.
      1. From the navigation bar, click the Devices menu and select Object Manager.
      2. Choose an object from the list of type Virtual WAN Link / Virtual WAN Link (Fortinet FortiGate) or Interface / Interface (Fortinet FortiGate) for which you want to view the metadata.
      3. Click Edit metadata in the Actions column to open the Edit Metadata pop-up.

        Fortinet Object Metadata

Note:

The TopN Report Views are automatically imported and are listed as shown below. Manual importing is not required for these reports.

  • FortiGate - Aggregate Links Utilization - In & Out
  • FortiGate - CPU Utilization
  • FortiGate - Device Reachability
  • FortiGate - Disk Utilization
  • FortiGate - Highest Interface Errors
  • FortiGate - ICMP Response Time
  • FortiGate - Memory Utilization
  • FortiGate - Most Utilized Interface - In
  • FortiGate - Most Utilized Interface - Out
  • FortiGate - Most Utilized Interfaces - In & Out
  • FortiGate - Packet Loss - ICMP from SevOne
  • FortiGate - Performance SLA - Jitter
  • FortiGate - Performance SLA - Latency
  • FortiGate - Performance SLA - Packet Loss
  • FortiGate - Performance SLA - State, Pkt Loss, Jitter, Latency
  • FortiGate - Total Errors and Discards
  • FortiGate - Tunnel Utilization - In & Out

Fortinet DNC / Flow Specific Changes in SevOne NMS

Flow Interface Manager

To check the flows received on SevOne NMS, from the navigation bar, click the Administration menu, select Flow Configuration, and then select Flow Interface Manager.

Flow Interface Manager

Deny 'Router-Generated' on Flow Rules

Fortinet forwards duplicate flow records for the same connection. So, it is necessary to deny flow from the Router Generated interface to avoid double counting. To create a rule, click the Administration menu, select Flow Configuration, and then select Flow Rules.

Please refer to Flow Rules for details.

Flow Rules

To configure additional parameters in the SD-WAN Flow Views options template, please refer to SD-WAN Flow Views Additional Configuration Guide

Support Long Flows on SevOne NMS

Warning: Sometimes, the flows are dropped when FortiGate devices send flows with a longer duration than what is configured. To allow long flows, from the navigation bar, click the Administration menu and select Cluster Manager and click on Cluster Settings tab, select the FlowFalcon subtab, and uncheck Drop Long Flows field.

Drop Long Flows

Solution Verification & Customization

Perform the following steps to log onto your SevOne NMS appliance.
Note: For more details, please refer to the Login page.
  1. Enter the URL for the SevOne NMS appliance into your web browser to display the Login page.
  2. Enter the credentials and click Login. For example, Username: admin and Password: SevOne
  3. To check MIB files imported, click the Administration menu, select Monitoring Configuration, and then select MIB Manager.

    Please refer to MIB Manager for details.

    MIBs Imported

  4. To check device groups imported, click the Devices menu and select Grouping, then Device Groups.

    Please refer to Device Groups for details.

    Device Groups

  5. To check object groups imported, click the Devices menu, select Grouping, and then select Object Groups.

    Please refer to Object Groups for details.

    Object Groups

    Important: You can change the Object Group Membership Rules based on your network environment.
  6. To check object types, click on the Administration menu and select Monitoring Configuration, then Object Types.

    Please refer to Object Types for details.

    Fortinet Object Types

Fortinet OOTB Reports in SevOne Data Insight

Note: Please refer to Data Insight 8.0 Guides for details.
  1. Log in to your SevOne Data Insight by navigating to the appropriate URL in your web browser. Enter your credentials on the login page and click Login.
  2. Click on the Reports, to view the Report Manager page. Under SevOne Folders, select Fortinet folder from the SD-WAN drop-down list. Select the desired Fortinet Report displayed. You can either click on the Run button as shown here or click on the report link directly to view detailed OOTB reports.

    Fortinet Reports in Manager

    Note: The following reports get imported.
    • FortiGate Device Summary
    • FortiGate Interface Summary
    • FortiGate Performance SLA Tests
    • FortiGate Tunnel Summary
    • Fortinet FortiGate Dashboard
  3. Click on Devices to view the Device Manager page, then select the relevant datasource from the Datasource drop-down list to view the corresponding devices and their details.

    Example

    Fortinet Device Manager