GoogleCloudPlatform / GoogleCloudPlatform/pubsec-declarative-toolkit

Validate fortigate GC-CAP/GC-TIP architecture - dual LB sandwich or VDOM config

Open
#158 6 comments 0 reactions 1 assignee Claimed by @fmichaelobrien View on GitHub
compliance documentation fortinet Landing Zone Networking
Dominant language
Shell
Stars
36
Forks
26
PR merge metrics
No merged PRs in 30d

Description

- see #446
- see https://github.com/GoogleCloudPlatform/pbmm-on-gcp-onboarding/issues/45
- Fortinet Fortigate config
- The guidance on the KCC LZ project is that we use a single cluster (3 VMs tbd) for both gc-cap and gc-tip and use flow separation or the existing LB sandwich architecture and 2 clusters of 2VMs for CAP/TIP separation.
- See TF PBMM LZ https://github.com/GoogleCloudPlatform/pbmm-on-gcp-onboarding/issues/45
- Verify the config and shadow deployment of a VDOM fortigate configaration - thanks Dave (triple fortigate zone for example)
- https://docs.fortinet.com/document/fortigate/6.0.0/cookbook/154890/vdom-configuration

https://github.com/GoogleCloudPlatform/pubsec-declarative-toolkit/blob/dev/solutions/landing-zone/architecture.md#di-24-validate-vdom---virtual-domain-fortigate-zone-isolation

# notes
- https://cloud.google.com/architecture?category=networking&text=appliance to https://cloud.google.com/architecture/deploying-nat-gateways-in-a-hub-and-spoke-architecture-using-vpc-network-peering-and-routing?hl=en

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.