Securing multiple landing zones with a transit VPC and Fortigate firewalls
This deployment guide describes a scenario for securing multiple landing zones using a transit VPC architecture with FortiGate firewalls on IBM Cloud.
- Add a dedicated interface for public connectivity
- Architecture details:
- Configure the firewall policy
- Configure the static routes on Fortigate
- Create a Public Address Range subnet and route the public traffic
- Deployment
- Enabling spoofing
- Fortigate appliances description
- FortiGate Deployment (HA Single Zone)
- From Internet to Spoke Virtual Servers for VPCs and from Spoke Virtual Servers for VPCs to internet
- From Power (DL) to Spokes and vice versa
- From server connected via the VPN to Spokes and vice versa
- From Spoke 1 to Spoke 2
- Overview
- Related resources
- Testing the High Availability failover
- Tutorial, testing connectivity