Section 2: Deploying FortiManager in AWS
In this section, you will deploy FortiManager-VM in AWS using the Fortinet CSE INTL GitHub repository.
Important
Before launching the CloudFormation template, you must subscribe to the FortiManager BYOL image in AWS Marketplace. If this step is skipped, the CloudFormation deployment may fail.
2.1 Subscribe to the FortiGate and FortiManager BYOL AMIs
Subscribe to the FortiGate and FortiManager BYOL AMIs before deployment. The following procedure should be completed for both products. Click the links below.
AWS Marketplace : FortiManager BYOL AMI Listing
AWS Marketplace : FortiGate BYOL AMI Listing
Follow the steps below:
- Click "View purchase options"
View purchase options- Review the subscription terms and click "Subscribe"
SubscribeWait for both Marketplace subscriptions to become active.
2.2 FortiManager Deployment in AWS
Deployment selection:
FortiManager Standalone (New VPC)GitHub Repository for deploying FortiManager
This deployment creates a new AWS VPC and deploys FortiManager-VM into that new VPC.
Objectives
By the end of this section, you will be able to:
- Launch the FortiManager New VPC CloudFormation template.
- Deploy FortiManager in AWS.
- Collect the FortiManager access information.
- Log in to the FortiManager GUI.
Before You Begin
Confirm that you have the following information from your instructor:
| Item | Example / Notes |
|---|---|
| EC2 key pair | Created in Section 1 |
| Allowed management CIDR | Your public IP or instructor-provided CIDR |
| FortiFlex token ID | Provided by instructor |
Important
Do not share AWS credentials, FortiManager passwords, API keys, FortiFlex credentials, or license information.
2.3 FortiManager Deployment Template
Open the Fortinet CSE INTL FortiManager repository:
GitHub Repository for deploying FortiManager
Locate:
FortiManager Standalone (New VPC)2.4 Launch the CloudFormation Stack
Under FortiManager Standalone (New VPC), click:
textLaunch StackConfirm that the CloudFormation page opens in:
texteu-central-1Click:
textNext
2.5 Configure Stack Parameters
Use the values provided by your instructor.
Suggested values:
| Parameter | Value |
|---|---|
| Stack name | student<number> |
| VPCCIDR | Default |
| PublicSubnet | Default |
| PublicSubnetRouterIP | Default |
| AZForFMG | AZ in eu-central-1 |
| FMGInstanceType | Default |
| FortiManagerVersion | 7.6.x; verify the deployed release is 7.6.4 or later before continuing |
| LicenseType | FortiFlex |
| FortiFlexTokenID | Provided by instructor |
| CIDRForFMGccess | Instructor-approved management source CIDR; use the actual parameter label in the selected template |
| Key pair | Created EC2 key pair in Section 1 |
| EncryptVolumes | false |
2.6 Create the Stack
Review the stack configuration.
Confirm that:
- Region is
eu-central-1. - Deployment option is New VPC.
LicenseTypeis set toFortiFlex.- Key pair is correct.
- Region is
Click the box
I acknowledge that AWS CloudFormation might create IAM resources.Click:
textCreate stackWait until the stack status becomes:
textCREATE_COMPLETE
2.7 Collect FortiManager Access Information
After the stack is complete:
Open the EC2 console to find out FortiManager public IP.
Find the public IP assigned to FortiManager.
Access the FortiManager GUI using the assigned public IP.
The first password is the EC2 instance ID. You will need to change it after first login.
Example:
FortiManager URL: https://<fortimanager-public-ip>
FortiManager Username: admin
FortiManager Password: <Instance-ID>- Record the FortiManager access information in your private notes.
- Check the installed firmware version. This automatic-onboarding workflow requires FortiManager 7.6.4 or later in the 7.6 branch and FortiOS 7.6.5 or later; the Terraform lab selects FortiOS 7.6.7. The template selects a current AMI within the chosen branch, so verify the actual version instead of assuming any 7.6 release supports the workflow. Fortinet feature requirements
Do Not Share
Do not share FortiManager credentials.
2.8 Enable FortiManager Management of VM Devices
Before continuing with the UMS and Auto Scaling configuration, FortiManager must be configured to allow management of VM devices.
This is required so FortiManager can manage the FortiGate-VM instances that will be deployed later by the Auto Scaling Group.
Log in to the FortiManager CLI via GUI or SSHv2 session, and run the following commands:
config system global
set fgfm-allow-vm enable
endThis enables VM-device management. The API administrator, AWS connector, UMS, FortiFlex and onboarding settings in Sections 3–7 are still required.
Keep the FortiManager EC2 Name tag identifiable, for example student01-FortiManager.
2.9 Allow FortiGate Registration and Management Traffic
The CloudFormation parameter CIDRForFMGccess controls the source range allowed into FortiManager. Setting it to your browser's public IP alone does not allow FortiGates in the separate security VPC to register through FortiManager's public IP.
Before Stage 2, open the FortiManager EC2 instance's Security → Security groups → Inbound rules and ensure these paths are allowed:
| Traffic | Destination port | Source |
|---|---|---|
| BYOL automatic registration/license request | TCP 443 | FortiGate management public egress addresses |
| IPv4 FGFM management | TCP 541 | FortiGate management public egress addresses |
| Browser administration | TCP 443 | Your browser/instructor management source |
This lab dynamically allocates FortiGate management public IPs as the ASG launches members. For the isolated classroom deployment, permit TCP 443 and 541 from 0.0.0.0/0 so initial onboarding and later scale-out do not depend on manually adding each new IP. Keep SSH access limited to your management source. A restricted deployment needs an instructor-provided stable egress range or private management design instead.
If the template's existing rule already permits all traffic from 0.0.0.0/0, these ports are already allowed; do not add duplicate rules. Confirm API administrator trusted-host restrictions also permit the FortiGate source addresses.