Section 9: Stage 1 — Deploy Infrastructure with Terraform
In this section, use the Cloud9 Terraform workstation from Section 8 to create the GWLB, networking, web-demo infrastructure and an empty FortiGate ASG. No FortiGates launch in Stage 1. Section 10 prepares FortiManager and then activates the ASG in Stage 2.
Use the Cloud9 workstation prepared in Section 8 for the commands below. Keep the Terraform configuration and state in that same workspace throughout the lab.
Objectives
By the end of this section, you will be able to:
- Open the Cloud9 Terraform workstation.
- Confirm AWS account and region access.
- Download the Fortinet AWS Terraform module package.
- Edit the
terraform.tfvarsfile for an Auto Scaling Group deployment. - Add FortiManager integration variables.
- Run Terraform initialization and deployment commands from Cloud9.
- Verify an empty ASG and collect the GWLB addresses before FortiManager provisioning is configured.
Before You Begin
Confirm that you have completed the previous sections and have the following information from your instructor:
| Item | Description | Example |
|---|---|---|
| Cloud9 environment | Cloud9 Terraform workstation deployed in Section 8 | student01-Cloud9-New-VPC |
| AWS Console access | Access to the AWS account used for the lab | Instructor-provided |
| AWS region | Region where the deployment will run | eu-central-1 |
| FortiManager IP address | Public IP address of FortiManager for this lab | x.x.x.x |
| FortiManager serial number | FortiManager VM serial number | FMG-VMXXXXXXXXXX |
| FortiManager administrator password | Your current FortiManager password; BYOL registration uses the API key below | Instructor-provided or set during initial login |
| FortiManager API admin key | API key generated from FortiManager | Created in Section 3 |
Important
Use the same AWS region throughout the lab.
For this lab, the AWS region is:
eu-central-1Step 1: Return to the Cloud9 IDE Home Directory
Before cloning the Fortinet repository, return to your Cloud9 home directory.
cd ~Step 2: Clone the Lab Repository
Clone the lab repository, which includes the Terraform modules and two-stage deployment configuration.
mkdir -p ~/environment
cd ~/environment
git clone https://github.com/ozanoguz/aws-ums-hol.gitStep 3: Go to the Auto Scaling Group Example Directory
Use this lab repository and the following example; the upstream examples do not include all of this lab's web-demo additions.
cd aws-ums-hol/terraform/examples/spk_gwlb_asg_fgt_gwlb_igwStep 4: Configure the Terraform Variables
For a new lab, create the working variables file from the supplied backup only if it does not already exist:
if [ ! -f terraform.tfvars ]; then
cp terraform.tfvars.backup terraform.tfvars
fi
nano terraform.tfvarsTerraform automatically loads terraform.tfvars, but not terraform.tfvars.backup. Edit the working file and replace every placeholder, including <YOUR-OWN-VALUE>, <FMG-IP>, <FMG-SN> and <FMG-API-KEY>. The backup already selects deployment_stage = "infrastructure" and configures the later active baseline as minimum 2, desired 2, maximum 3. Preserve an existing working file and its deployment values; running labs must use active.
Suggested Values to Configure Before Proceeding
Root Config Section (Suggested Values)
| Variable | Description | Value |
|---|---|---|
| access_key | Provided by instructor | Example syntax, use your own value: "<YOUR_AWS_ACCESS_KEY_ID>" |
| secret_key | Provided by instructor | Example syntax, use your own value: "<YOUR_AWS_SECRET_ACCESS_KEY>" |
| region | AWS region name | "eu-central-1" |
VPC Section (Suggested Values)
| Variable | Description | Value |
|---|---|---|
| vpc_cidr_block | VPC CIDR block for auto scale group | "10.0.0.0/16" |
| spoke_cidr_list | CIDRs of the existing spoke VPCs | ["10.1.0.0/16"] |
| availability_zones | AWS Availability Zones | ["eu-central-1a", "eu-central-1b"] |
Auto Scale Group Section: fgt_byol_asg Configuration
| Variable | Description | Value |
|---|---|---|
| fgt_version | FortiGate version | Already configured for you "7.6.7" |
| license_type | FortiGate license type | "byol" |
| fgt_password | FortiGate password | Example syntax: "Fortinet2026!" |
| keypair_name | Name of the key pair | Example syntax, use your key pair name: "student01-key" |
| user_conf_file_path | Must be empty | Already configured for you "" |
| enable_fgt_system_autoscale | Disable legacy Lambda autoscale handling; UMS remains enabled by fmg_integration.ums | false |
| asg_min_size | Minimum capacity for the two-node baseline | 2 |
| asg_desired_capacity | Stage 2 FortiGate instance count | 2 |
| asg_max_size | Allow the later three-node scale-out exercise | 3 |
Capacity note: the 2/2/3 values above apply only in Stage 2 (active). Stage 1 (infrastructure) overrides all three to zero; leave the baseline values in the file.
FortiManager Configuration: fmg_integration Section
| Variable | Description | Value |
|---|---|---|
| ip | FortiManager public IP address | "FORTIMANAGER PUBLIC IP" |
| sn | FortiManager Serial Number | "FMVMELTMXXXXXXXX" |
| autoscale_psksecret | Pre-shared Key for 'config system autoscale' | "Fortinet2026!" |
| fmg_password | Current FortiManager password; used for PAYG, not BYOL API-key registration, keep empty. | "" |
| api_key | Created in Section 3 | "<YOUR_FORTIMANAGER_API_KEY>" |
Replace the example values below with your own FortiManager details. This block is nested inside asgs.fgt_byol_asg:
fmg_integration = {
ip = "<YOUR_FORTIMANAGER_IP>"
sn = "<YOUR_FORTIMANAGER_SERIAL>"
fgt_lic_mgmt = "fmg"
ums = {
autoscale_psksecret = "<YOUR_AUTOSCALE_PSK>"
hb_interval = 10
fmg_password = ""
api_key = "<YOUR_FORTIMANAGER_API_KEY>"
}
}Keep fgt_intf_mode = "2-arm" and enable_cross_zone_load_balancing = true. The supplied web_demo block already enables public HTTP/80 on a separate 10.50.0.0/16 demo spoke; no browser-IP restriction needs to be added. Syslog uses private peering.
Check the capacity fields above even if the file contains values from an earlier run: a maximum of 1 prevents the scale-out exercise. Confirm your FortiFlex configuration has enough capacity/entitlements for three FortiGates.
Save in nano with Ctrl+O, press Enter, then Ctrl+X. Use Control, not Command, on a Mac.
Select Stage 1: Infrastructure Only
For a new lab, confirm this top-level setting copied from the backup is present in terraform.tfvars:
deployment_stage = "infrastructure"Keep the ASG values in the table above at minimum 2, desired 2, maximum 3. Stage 1 overrides the effective minimum, desired and maximum to 0, and disables configured scaling policies. Terraform still creates the ASG, launch template, GWLB and networking, but no FortiGate can launch before the onboarding configuration is ready.
Ensure the top-level demo configuration is present:
web_demo = {
allowed_client_cidrs = ["0.0.0.0/0"]
vpc_cidr = "10.50.0.0/16"
}Existing deployments
Do not change a running lab to infrastructure; zero capacity can terminate its FortiGates. Leave it at active (the default when omitted) and use Section 10's existing-device installation steps. Preserve your current Terraform state and workspace.
Step 5: Initialize Terraform
Run Terraform initialization from the example directory.
terraform initConfirm that Terraform downloads the required providers and modules successfully.
Step 6: Review the Terraform Plan
Generate and review the Terraform execution plan.
terraform plan -out=infrastructure.planReview the resources that Terraform will create or modify. Confirm the plan contains an empty ASG with minimum, desired and maximum capacity zero, plus the GWLB and web-demo resources. If you edit the configuration afterward, regenerate the saved plan.
Step 7: Apply Stage 1 — Infrastructure
Deploy the infrastructure.
terraform apply infrastructure.planTerraform will create or update the AWS resources.
Step 8: Verify Stage 1
After Terraform completes, verify the following:
- The Auto Scaling Group exists with desired capacity 0 and no FortiGate instances.
- The GWLB and its network interfaces exist, so their private IPs can be retrieved.
- The web-demo infrastructure exists. Its page need not respond yet because no FortiGate is inspecting traffic.
terraform output deployment_stagereportsinfrastructure.
No UMS group in FortiManager yet
Managed FortiGate (0) and no BYOL ASG device group are expected in Stage 1. Verify the empty ASG in the AWS EC2 → Auto Scaling Groups console. FortiManager creates its UMS device group after the first FortiGate is authorized in Stage 2. Do not create the UMS group manually or launch a FortiGate early to make it appear. Fortinet group-creation behavior
The web URL remains unavailable until Section 10 completes FortiManager configuration, activates the ASG and installs the inspection and outbound policies through onboarding. Keep your Terraform state files; subsequent changes must use this same deployment state.
Next: Configure Inspection and the Web Demo
Continue to Section 10: Configure FortiManager and Activate the ASG. Create both scripts, populate the policy package and update onboarding before changing the deployment stage to active. The first two FortiGates then receive their configuration through onboarding; a separate installation path covers existing devices.