Skip to content

Lab Guide: Deploy and Configure FortiManager UMS on AWS ​

Quick Navigation ​


Overview ​

In this lab, you will configure FortiManager for AWS User Managed Scaling (UMS) integration by following the official Fortinet AWS Administration Guide.

Each student will use an individual AWS account. AWS access keys and secret access keys have already been created by the instructor.

The lab uses two Terraform stages in the same directory, backend and workspace:

SectionStageExpected result
9infrastructureGWLB, networking, web-demo infrastructure and an empty ASG; zero FortiGates
10, Steps 1–6Prepare FortiManagerTemplates, populated policy package and onboarding rule ready using the deployed GWLB addresses
10, Step 7activeTwo FortiGates launch and receive configuration through onboarding
11–12Validate and scaleVerify inspection, scale to three using UMS, then return to two

Section 10, Step 8 covers manual installation for already registered devices. Existing running labs should remain active; switching to infrastructure requests scale-in to zero.

Official Fortinet reference


Lab Objectives ​

By the end of this lab, you will be able to:

  • Log in to your assigned AWS account.
  • Confirm your AWS identity and region.
  • Deploy and access FortiManager.
  • Create a FortiManager API administrator.
  • Configure a FortiManager AWS Cloud SDN connector.
  • Create an auto-onboarding rule.
  • Configure a FortiFlex connector in FortiManager.
  • Deploy infrastructure first, then activate the FortiGate ASG after FortiManager is ready.
  • Validate that FortiManager can discover AWS Auto Scaling resources.
  • Install GENEVE, routing, syslog and the demo policy package through FortiManager.
  • Test the public HTTP web demo and identify actual inspection traffic.
  • Scale from two to three FortiGates through UMS, then return to two.

Lab Topology ​

Reference GWLB inspection architecture

The image shows the general multi-spoke GWLB architecture. Its 10.1.0.0/16 and 10.2.0.0/16 spokes are reference examples, not the web-demo addresses used in this lab. The deployed demo uses a separate 10.50.0.0/16 spoke: HTTP server 10.50.0.10, private syslog collector 10.50.0.11. The collector and HTTP service share one EC2 instance with two private addresses. FortiManager and the Terraform workstation are deployed separately and are not shown. Section 10 shows the lab's inspected HTTP and private telemetry paths.


Prerequisites ​

Before starting, confirm that you have received the following from your instructor:

ItemExample / Notes
Credential portal URLProvided by instructor
Student IDExample: student01
Lab access keyProvided by instructor
AWS Console URLhttps://console.aws.amazon.com/
AWS account IDProvided by instructor
AWS IAM usernameProvided by instructor
AWS passwordProvided by instructor
AWS access key IDProvided by instructor
AWS secret access keyProvided by instructor
AWS regioneu-central-1
FortiManager URLObtained after deployment in Section 2
FortiFlex token IDProvided by instructor
FortiCloud API user & passwordProvided by instructor

Credential portal

If your instructor provides a credential portal URL, open it and enter the shared lab access key and your assigned Student ID. The portal returns the AWS, FortiCloud, and FortiFlex values used throughout this lab.

Important

Do not share your AWS access key, secret access key, FortiManager password, API key, or license files with other students.


Naming Convention ​

Use the following naming convention throughout the lab:

text
student<number>

Example:

text
student01-FortiManager
student01-FMG-API-admin
student01-AWS-SDN-Connector
student01-Onboarding-Rule
student01-Fortiflex-Connector

Replace <number> with your assigned student number.


Start the Lab ​

Start with:

Section 1: Log in to AWS

AWS UMS Hands-on Lab Guide