Deployment Guide¶
Tested locally via MkDocs. Validate against your Azure/FortiOS versions.
Prereqs¶
- Azure subscription + RBAC
- FortiGate with SD-WAN overlays configured
- Tooling: PowerShell 7+, Python 3.11+ (or 3.13), MkDocs
Steps¶
- Prepare address objects & phase1/phase2 proposals
- Create/verify Azure vWAN or hub VNet
- Provision IPsec tunnel(s) and BGP (optional)
- Add/validate UDRs, route propagation, firewall policies
- Test flows (ICMP, TCP 443, custom), observe logs
- Stabilize timers and failover thresholds
Validation¶
- End-to-end ping + TCP test
- Route table checks (effective routes)
- FortiGate session table and IPSec SA states