An SD-WAN transit routing scenario with Google Network Connectivity Center (NCC) allows users to route data and exchange BGP routing information between two or more remote sites over the Google Cloud Platform Infrastructure.
Implementation is done by creating the NCC HUB and an endpoint (Spoke) for each remote site. In order to reduce Network latency, the Spoke is deployed in a Google Cloud region that is located geographically closest to the remote site for which it is created.
The script included in this repository deploys Internal/External VPCs, an NCC hub, Spokes, Cloud Routers, and FortiGate-VM (Router Appliance) instances.
- Deployed items are pre-configured with the variables that are read from the parameter file fortigate-ncc-param-zone1.json.
- The script deploys a Pay as You Go (PAYG) FortiGate-VM instance. A list of the Order types can be found at FortiGate Cloud VM Licensing Order Types.
-
Staging Server : A Linux environment can be used as a staging server. Alternatively, Google Cloud CLI can also be used to run the script.
- These must be installed on the runtime: googleapiclient, google.oauth2, google.auth, google.cloud.
- The packages PyJWT and cryptography must be installed using pip.
-
Authentication: Google Cloud Service Account.
- Create a Google Cloud Service account with Owner Rights.
- Create a Key in json format and copy it to your staging server (where your Python program will run).
-
Cloud Storage Bucket:
-
Create a Storage Bucket on GCP.
-
Edit the Parameters in "fortigate-ncc-param-zone1.json" as required. Template for this is provided in the fortigate-ncc-param-zone1.json.example file
-
Upload file to the bucket.
Files Required on the staging server (locally) : deploy-fortigate-ncc.py , JSON key created in step2
Files Required on the Cloud Bucket : fortigate-ncc-param-zone1.json
-
On the Staging server, Run the following command :
- python3 deploy-fortigate-ncc.py /$path/apikey.json storage-bucket-name1 fortigate-ncc-param-zone1.json
Please ensure to use the absolute path for the ApiKey
The Python scritp deploys different resources and it is required to have the required access rights and quota in your GCP subscription to deploy the resources.
- The template will deploy n1-standard-4 VMs for this architecture. Other VM instances are supported as well with a minimum of 2 NICs. A list can be found here
- Licenses for Fortigate : The Given script deploys a PAYG image.
- PAYG : This license is automatically generated during the deployment of the FortiGate systems.
Note: this solution has been tested in Python 3.7.7 and 3.8.5 runtime environments
Fortinet-provided scripts in this and other GitHub projects do not fall under the regular Fortinet technical support scope and are not supported by FortiCare Support Services. For direct issues, please refer to the Issues tab of this GitHub project. For other questions related to this project, contact github@fortinet.com.
License © Fortinet Technologies. All rights reserved.
