Skip to content

Section 9: Stage 1 — Deploy Infrastructure with Terraform ​

In this section, use the Cloud9 Terraform workstation from Section 8 to create the GWLB, networking, web-demo infrastructure and an empty FortiGate ASG. No FortiGates launch in Stage 1. Section 10 prepares FortiManager and then activates the ASG in Stage 2.

Use the Cloud9 workstation prepared in Section 8 for the commands below. Keep the Terraform configuration and state in that same workspace throughout the lab.


Objectives ​

By the end of this section, you will be able to:

  • Open the Cloud9 Terraform workstation.
  • Confirm AWS account and region access.
  • Download the Fortinet AWS Terraform module package.
  • Edit the terraform.tfvars file for an Auto Scaling Group deployment.
  • Add FortiManager integration variables.
  • Run Terraform initialization and deployment commands from Cloud9.
  • Verify an empty ASG and collect the GWLB addresses before FortiManager provisioning is configured.

Before You Begin ​

Confirm that you have completed the previous sections and have the following information from your instructor:

ItemDescriptionExample
Cloud9 environmentCloud9 Terraform workstation deployed in Section 8student01-Cloud9-New-VPC
AWS Console accessAccess to the AWS account used for the labInstructor-provided
AWS regionRegion where the deployment will runeu-central-1
FortiManager IP addressPublic IP address of FortiManager for this labx.x.x.x
FortiManager serial numberFortiManager VM serial numberFMG-VMXXXXXXXXXX
FortiManager administrator passwordYour current FortiManager password; BYOL registration uses the API key belowInstructor-provided or set during initial login
FortiManager API admin keyAPI key generated from FortiManagerCreated in Section 3

Important

Use the same AWS region throughout the lab.

For this lab, the AWS region is:

text
eu-central-1

Step 1: Return to the Cloud9 IDE Home Directory ​

Before cloning the Fortinet repository, return to your Cloud9 home directory.

bash
cd ~

Step 2: Clone the Lab Repository ​

Clone the lab repository, which includes the Terraform modules and two-stage deployment configuration.

bash
mkdir -p ~/environment
cd ~/environment
git clone https://github.com/ozanoguz/aws-ums-hol.git

Step 3: Go to the Auto Scaling Group Example Directory ​

Use this lab repository and the following example; the upstream examples do not include all of this lab's web-demo additions.

bash
cd aws-ums-hol/terraform/examples/spk_gwlb_asg_fgt_gwlb_igw

Step 4: Configure the Terraform Variables ​

For a new lab, create the working variables file from the supplied backup only if it does not already exist:

bash
if [ ! -f terraform.tfvars ]; then
  cp terraform.tfvars.backup terraform.tfvars
fi
nano terraform.tfvars

Terraform automatically loads terraform.tfvars, but not terraform.tfvars.backup. Edit the working file and replace every placeholder, including <YOUR-OWN-VALUE>, <FMG-IP>, <FMG-SN> and <FMG-API-KEY>. The backup already selects deployment_stage = "infrastructure" and configures the later active baseline as minimum 2, desired 2, maximum 3. Preserve an existing working file and its deployment values; running labs must use active.


Suggested Values to Configure Before Proceeding ​

Root Config Section (Suggested Values) ​

VariableDescriptionValue
access_keyProvided by instructorExample syntax, use your own value: "<YOUR_AWS_ACCESS_KEY_ID>"
secret_keyProvided by instructorExample syntax, use your own value: "<YOUR_AWS_SECRET_ACCESS_KEY>"
regionAWS region name"eu-central-1"

VPC Section (Suggested Values) ​

VariableDescriptionValue
vpc_cidr_blockVPC CIDR block for auto scale group"10.0.0.0/16"
spoke_cidr_listCIDRs of the existing spoke VPCs["10.1.0.0/16"]
availability_zonesAWS Availability Zones["eu-central-1a", "eu-central-1b"]

Auto Scale Group Section: fgt_byol_asg Configuration ​

VariableDescriptionValue
fgt_versionFortiGate versionAlready configured for you "7.6.7"
license_typeFortiGate license type"byol"
fgt_passwordFortiGate passwordExample syntax: "Fortinet2026!"
keypair_nameName of the key pairExample syntax, use your key pair name: "student01-key"
user_conf_file_pathMust be emptyAlready configured for you ""
enable_fgt_system_autoscaleDisable legacy Lambda autoscale handling; UMS remains enabled by fmg_integration.umsfalse
asg_min_sizeMinimum capacity for the two-node baseline2
asg_desired_capacityStage 2 FortiGate instance count2
asg_max_sizeAllow the later three-node scale-out exercise3

Capacity note: the 2/2/3 values above apply only in Stage 2 (active). Stage 1 (infrastructure) overrides all three to zero; leave the baseline values in the file.

FortiManager Configuration: fmg_integration Section ​

VariableDescriptionValue
ipFortiManager public IP address"FORTIMANAGER PUBLIC IP"
snFortiManager Serial Number"FMVMELTMXXXXXXXX"
autoscale_psksecretPre-shared Key for 'config system autoscale'"Fortinet2026!"
fmg_passwordCurrent FortiManager password; used for PAYG, not BYOL API-key registration, keep empty.""
api_keyCreated in Section 3"<YOUR_FORTIMANAGER_API_KEY>"

Replace the example values below with your own FortiManager details. This block is nested inside asgs.fgt_byol_asg:

hcl
fmg_integration = {
  ip           = "<YOUR_FORTIMANAGER_IP>"
  sn           = "<YOUR_FORTIMANAGER_SERIAL>"
  fgt_lic_mgmt = "fmg"
  ums = {
    autoscale_psksecret = "<YOUR_AUTOSCALE_PSK>"
    hb_interval         = 10
    fmg_password        = ""
    api_key             = "<YOUR_FORTIMANAGER_API_KEY>"
  }
}

Keep fgt_intf_mode = "2-arm" and enable_cross_zone_load_balancing = true. The supplied web_demo block already enables public HTTP/80 on a separate 10.50.0.0/16 demo spoke; no browser-IP restriction needs to be added. Syslog uses private peering.

Check the capacity fields above even if the file contains values from an earlier run: a maximum of 1 prevents the scale-out exercise. Confirm your FortiFlex configuration has enough capacity/entitlements for three FortiGates.

Save in nano with Ctrl+O, press Enter, then Ctrl+X. Use Control, not Command, on a Mac.


Select Stage 1: Infrastructure Only ​

For a new lab, confirm this top-level setting copied from the backup is present in terraform.tfvars:

hcl
deployment_stage = "infrastructure"

Keep the ASG values in the table above at minimum 2, desired 2, maximum 3. Stage 1 overrides the effective minimum, desired and maximum to 0, and disables configured scaling policies. Terraform still creates the ASG, launch template, GWLB and networking, but no FortiGate can launch before the onboarding configuration is ready.

Ensure the top-level demo configuration is present:

hcl
web_demo = {
  allowed_client_cidrs = ["0.0.0.0/0"]
  vpc_cidr            = "10.50.0.0/16"
}

Existing deployments

Do not change a running lab to infrastructure; zero capacity can terminate its FortiGates. Leave it at active (the default when omitted) and use Section 10's existing-device installation steps. Preserve your current Terraform state and workspace.

Step 5: Initialize Terraform ​

Run Terraform initialization from the example directory.

bash
terraform init

Confirm that Terraform downloads the required providers and modules successfully.


Step 6: Review the Terraform Plan ​

Generate and review the Terraform execution plan.

bash
terraform plan -out=infrastructure.plan

Review the resources that Terraform will create or modify. Confirm the plan contains an empty ASG with minimum, desired and maximum capacity zero, plus the GWLB and web-demo resources. If you edit the configuration afterward, regenerate the saved plan.


Step 7: Apply Stage 1 — Infrastructure ​

Deploy the infrastructure.

bash
terraform apply infrastructure.plan

Terraform will create or update the AWS resources.


Step 8: Verify Stage 1 ​

After Terraform completes, verify the following:

  1. The Auto Scaling Group exists with desired capacity 0 and no FortiGate instances.
  2. The GWLB and its network interfaces exist, so their private IPs can be retrieved.
  3. The web-demo infrastructure exists. Its page need not respond yet because no FortiGate is inspecting traffic.
  4. terraform output deployment_stage reports infrastructure.

No UMS group in FortiManager yet

Managed FortiGate (0) and no BYOL ASG device group are expected in Stage 1. Verify the empty ASG in the AWS EC2 → Auto Scaling Groups console. FortiManager creates its UMS device group after the first FortiGate is authorized in Stage 2. Do not create the UMS group manually or launch a FortiGate early to make it appear. Fortinet group-creation behavior

The web URL remains unavailable until Section 10 completes FortiManager configuration, activates the ASG and installs the inspection and outbound policies through onboarding. Keep your Terraform state files; subsequent changes must use this same deployment state.

Next: Configure Inspection and the Web Demo ​

Continue to Section 10: Configure FortiManager and Activate the ASG. Create both scripts, populate the policy package and update onboarding before changing the deployment stage to active. The first two FortiGates then receive their configuration through onboarding; a separate installation path covers existing devices.

AWS UMS Hands-on Lab Guide