Prerequisites
Cisco Side
Before the FortiGate Connector for Cisco ACI can be successfully deployed, a number of prerequisites need to be satisfied within the Cisco environment.
One of the following Cisco ACI environments needs to be in place:
- Cisco ACI v1.1(2h) l Cisco ACI v1.1(3f)
Within the Cisco ACI, the following configurations need to be completed before Layer 4 -7 Services (in this case, the FortiGate Connector) can be deployed:
- Creation of Access Policies configuration under Fabric menu l Creation of any need Tenant(s) l Creation of Network(s) (including Bridge Domain) l Creation of Application Profile(s) l Creation of End Point Group(s) l Creation of Contract(s)
For detail, please consult Cisco APIC deployment Guide.
http://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/1-x/L4-L7_Services_ Deployment/guide/b_L4L7_Deploy.html
FortiGate Side
Before the FortiGate Connector for Cisco ACI can be successfully deployed, a number of prerequisites need to be satisfied on the FortiGate side of the equation.
Physical Firewall
- Configure administrator user name and password.
- Enable http/https on mgmt. port.
- Configure IP address in mgmt. port.
- Enable VDOM-Admin globally.
- Configure Port-Group if needed.
VM Firewall
- Assign network ports before start VM
- Configure administrator user name and password.
- Enable http/https on mgmt. port.
- Configure IP address in mgmt. Ports
- Enable VDOM-Admin globally