Skip to content
CBT Nuggets
DemoBook a Demo

Building a Fortinet SD-WAN Lab

This skill, led by Keith Barker, focuses on building and configuring a Fortinet SD-WAN lab. It covers the setup of a lab environment using FortiGate devices, including the configuration of VLANs, routing, and NAT policies. The skill also delves into network troubleshooting and the use of tools like EVE-NG to simulate various network conditions. Learners will gain hands-on experience in designing, implementing, and verifying SD-WAN configurations in a controlled lab setting.

Full skill from Fortinet NSE 7. Preview the IT training 23,000+ organizations trust.

56m

Skill 1 of 10 in Fortinet NSE 7

Overview

Join Keith Barker as he describes and demonstrates building a Fortinet SD-WAN lab.

Recommended Experience

  • 2 to 5 years of networking experience

Related Job Functions

  • Network Admin
  • Network Engineer

Keith discovered a love for computers and networking in 1984 and began his IT career in 1985. He specializes in networking and security.

Intro to Building a Fortinet SD-WAN Lab

Keith introduces this set of videos.

SD-WAN Overview

Keith presents an overview of Fortinet Secure SD-WAN.

Knowledge Check

What type of SD-WAN is being used when the FortiGate provides direct access to the Internet for users, without forwarding through a tunnel first?

SD-WAN Lab Design

Keith walks through a design plan for the SD-WAN lab.

Knowledge Check

In our design, which network address space is being used for Internet Service Provider B?

Prepping the DC-10 FortiGate

Keith demonstrates the initial configuration for the DC-10 FortiGate in the SD-WAN lab.

Knowledge Check

What is the default ISP being used on DC-10 for internet access?

Test and Verify DC-10

Keith demonstrates the testing and verification of the DC-10 FortiGate in the SD-WAN lab.

Knowledge Check

What is the next-hop address for the default route on DC-10?

Behind the Curtain

Keith shares the details that are used behind the scenes to enable various network conditions through each of the service providers.

Knowledge Check

In the lab, what is being used that allows the introduction of delay and/or jitter for any of the service provider connections?

Conclusion

I hope this has been informative for you and I would like to thank you for consuming.

View Transcript

Intro to Building a Fortinet SD-WAN Lab

0:00[AUDIO LOGO]

0:07Hello, and welcome.

0:09My name is Keith Barker.

0:10And the offering of SD-WAN, Software-Defined Wide Area

0:14Networking, from Fortinet, leveraging FortiGates,

0:16is a fantastic offering.

0:18However, to get it set up, we have

0:19to have some type of gear, whether it's

0:21physical or virtual or a combination of both.

0:24So in this set of videos, I'd like

0:26to watch you through the basic infrastructure

0:28setup for our lab environment.

0:30And then with that in place, in our subsequent sets of videos,

0:33we can go through the details of the implementation,

0:35verification and troubleshooting when

0:37necessary of SD-WAN in a Fortinet environment.

0:40So join me in the next video as we take a big-picture look

0:43at the world of SD-WAN from Fortinet.

SD-WAN Overview

0:00[AUDIO LOGO]

0:06It's often helpful to have kind of a big-picture understanding

0:09of what a feature or function or technology does.

0:12So in this video, you and I get to take just a few moments

0:14and chat about the big-picture idea behind SD-WAN

0:18in a Fortinet environment.

0:19So let's imagine that our company has a location.

0:22Let's call this the main site.

0:24And this main site could be, for example,

0:26our headquarters location.

0:27Or it could be the location of our big-data center.

0:30So let me go ahead and make that our site.

0:32We'll put a little rectangle there.

0:33And at that site, we have some internal networking going on.

0:37Maybe this is the 10.10 network here.

0:39And then for connectivity to the outside world,

0:41in a Fortinet environment, we're going to be using a FortiGate.

0:43So I'll put a FortiGate right here.

0:45If we wanted some fault tolerance,

0:46we could do high availability.

0:48And before we put the WAN connectivity in,

0:50let's also go ahead and draw a second site.

0:52This could be a branch office or a remote site.

0:55So I'll label this remote/branch.

0:57And at that location, they've also got some networking.

1:00So perhaps this is the 10.20 network address space

1:03they're using down here.

1:04And for our connectivity to the rest of the world,

1:06we'll draw another FortiGate down here

1:08at this branch office.

1:09So we'll call this up here FortiGate 1.

1:11We'll call this down here FortiGate 2.

1:13And let's also draw a cloud that represents the internet.

1:17And on the internet, there's tons of service providers

1:20that can act as ISPs to be the on-ramp

1:22or the connectivity point between a location

1:25like the main site or the remote site and the internet.

1:28So let me go ahead and draw some service providers here.

1:31So I'll go ahead and put one in blue here.

1:33We'll call this SP-A for Service Provider A. Let's

1:37do another one for service provider B.

1:39So there's service provider B. And for good measure,

1:42let's also bring in service provider C.

1:44So that's service provider C right here.

1:46So these three service providers can be options for connectivity

1:49from the main site over to the internet

1:51and from the branch office to the internet.

1:54And in addition to just internet access,

1:56we could also purchase some connectivity services

1:58from a provider that would lead to the internet

2:01or that can have these two sites connected together.

2:03So let's imagine that this represents an MPLS cloud.

2:06And MPLS stands for Multiprotocol Label Switching.

2:09And so service providers can use that and then logically

2:12provide circuits between various locations

2:15that they both support.

2:16So if the main site and remote site

2:17both want to use the service provider and MPLS services,

2:19that is yet another way for some wide area network connectivity.

2:23So the headquarters site to get to the internet,

2:25perhaps we have a FortiGate connected to this service

2:27provider, service provider A. And if we want some fault

2:29tolerance, we don't want to rely on just one service provider.

2:32And we have multiple options.

2:33We could also have another connection to another service

2:35provider.

2:36And assuming we had multiple service providers available

2:39and we had a budget for it, we can also use the third one.

2:42And for the MPLS connection, we could also have a connection

2:44there as well.

2:45So at the remote branch office, it's

2:47not likely to have all those connections.

2:49For example, they may be using service provider A

2:52and then have the MPLS as an alternate path.

2:54So let's imagine we have a user down here on this 10.20

2:57network.

2:57In fact, let me connect that FortiGate to that network.

2:59There we go.

2:59And let's also draw a little computer here

3:01at the branch office.

3:02So with this networking that we've currently

3:04drawn with our service providers,

3:06including one providing MPLS services,

3:08this represents our infrastructure

3:10for the wide area connectivity.

3:11Through service provider A, I'll go ahead and color code that.

3:14Or service provider B, color code that.

3:17And service provider C. Or leveraging the connectivity

3:20provided via the MPLS.

3:22And we can refer to that connectivity

3:24as the infrastructure or the underlay network.

3:27And the actual term underlay, if we're not

3:29going to do anything else with this,

3:30really is kind of a waste of words

3:32because it's just the actual network that's

3:34forwarding the traffic.

3:35However, what we can do on top of this is

3:37we can logically overlay a different logical topology.

3:41And the reason it's important to bring up

3:43the concept of underlay is because we're

3:45allowed to take a look at a concept

3:47where we're going to put on a different topology on top

3:49of this infrastructure.

3:51An example would be a set of VPN tunnels using IPsec.

3:55And effectively, what we're doing is

3:56we're overlaying on top of our infrastructure.

3:59We're overlaying this logical path with the VPNs.

4:01So let's take a look at examples of both.

4:03Let's imagine that we don't have any VPNs that are currently

4:06in use, and we have this client here

4:08at PC1 that's going to the internet.

4:09That traffic would be forwarded to its default gateway.

4:12That firewall would make a routing decision,

4:14forward it out to service provider

4:15A, who would then forward it out to the internet resource.

4:18So that's the path the traffic would take from this PC going

4:20to this server.

4:21We'll call it server 1.

4:22And then when server 1 responds, the response

4:24would come back this way through the internet,

4:26through the local service provider,

4:28and then forwarded down the FortiGate,

4:29who would then forward the response back to the client.

4:32However, we could set up the routing and IPsec

4:34on top of this so that clients' traffic from PC1

4:37going to the internet server, instead of going directly

4:39out through the service provider,

4:41logically could go through a tunnel.

4:43So I'm going to color code it here.

4:45This represents our IPsec tunnel.

4:47And then the FortiGate at the main site

4:49would go ahead and make a routing decision

4:51and forward it out one of the paths going out to the internet

4:54and to that server.

4:55Perhaps, in this example, we're using service provider C.

4:57And then the response will come back up to the FortiGate

5:00at the headquarters site.

5:01And then the response would be encrypted and sent back down

5:04to the FortiGate at the remote branch

5:06office, who'd then decrypt it and forward it over to the PC.

5:10So that's an example of an overlay network

5:12where we're intentionally putting

5:14on top of the existing infrastructure an IPsec VPN

5:17tunnel.

5:17So the traffic patterns and the logical topology

5:20changes based on using the naked or raw infrastructure

5:23and the underlay network as a transport

5:25network versus using the VPN and IPsec as an overlay.

5:29And here's a secret.

5:30If we are using our IPsec overlay, behind the scenes,

5:34we're still using the infrastructure

5:35to actually move the packets.

5:37So it's the infrastructure network

5:38that's moving the traffic from FortiGate 2 up to FortiGate 1.

5:42And at that point, they would be encrypted IPsec packets.

5:44And it's the infrastructure that's

5:46supporting the connectivity from FortiGate 1 out to the internet

5:49through service provider C.

5:50So I'll make a little note here that the overlay network

5:53uses the infrastructure or underlay network.

5:56And oftentimes, that's referred to also as the transport

5:59network.

6:00So the transport network is the network

6:02that actually forwards the actual packets

6:03along their path.

6:04So that means that layer 3 is making routing decisions.

6:07At layer 2, it's making forwarding decisions

6:10based on the layer 2 frames.

6:11So whenever you hear the concept of infrastructure or underlay

6:14or transport networks, think of like the raw, normal networks

6:18that are forwarding packets and frames along their path.

6:21Now, depending on how we implement our WAN connectivity

6:24here, sometimes we may have this FortiGate go directly

6:27out to the internet, like just using the underlay network

6:29and just forwarding it directly without forwarding it up

6:31to the headquarters site first.

6:33And when that FortiGate is providing direct internet

6:35access for its users, that's referred

6:37to DIA, Direct Internet Access.

6:40The alternative to that would be to go ahead and require traffic

6:43for this PC, if it's going to the internet,

6:45to actually be sent up to the headquarters site via a tunnel.

6:48And then the FortiGate at the headquarters site

6:50could go ahead and forward it out to its final destination

6:53using the overlay network.

6:54So when the network is configured

6:56so that the PC going to the internet

6:57has to be tunneled up to the headquarter or main site

6:59first before it goes out, that's referred to

7:01as Remote Internet Access, or RIA.

7:05And when we're doing a remote internet access,

7:07that also implies that we're leveraging our overlay or VPN

7:11network to go ahead and pull that off.

7:13So one of the questions that often comes up is, OK, why?

7:15Why are we sending this PC's traffic all the way up

7:18to the FortiGate at the headquarters site

7:20before we're sending it out?

7:21Why not just go ahead and use direct internet access instead

7:23of remote internet access?

7:25And the answer is, for security.

7:27So perhaps at the main site, we're

7:28doing tons of security checks.

7:30We have really tough firewall policies

7:32and, associated with those policies,

7:34security profiles implementing application control,

7:37URL filtering, antivirus/antimalware support,

7:41intrusion prevention services, data loss prevention.

7:44And the list goes on.

7:45And that'd be a fantastic reason to forward all the traffic

7:48with the remote internet access up to this site

7:50first before forwarding it out.

7:51And this IPsec VPN tunnel that goes

7:54between FortiGate 1 and FortiGate 2

7:55here, it doesn't have to use the ISP A.

7:58We could also do an IPsec tunnel that way

8:01using the MPLS network, if the traffic needs

8:03to go between FortiGate 1 and FortiGate 2.

8:05So it has options.

8:06So regarding this PC's traffic that

8:08needs to go out to the internet server, we have a few options.

8:11One would be to go ahead and use ISP A with direct internet

8:15access.

8:15Another option would be go ahead and send traffic

8:18through the VPN tunnel up to the main site to FortiGate 1,

8:21who would then forward it off to the internet.

8:23And that would be referred to as RIA, Remote Internet Access.

8:27And then a third option could be actually

8:29using the MPLS network also with remote internet access.

8:32And in that case, the client's traffic

8:34would be forwarded through the MPLS

8:36connection between FortiGate 2 and FortiGate 1.

8:38And then once again, at FortiGate 1,

8:40it would look at the traffic and then make a forwarding decision

8:42out to the internet.

8:43And for that connectivity from the client out to the server,

8:46perhaps we're using software as a service,

8:49maybe some mission-critical application that's

8:52being hosted in the cloud.

8:53The client's simply accessing it via the browser.

8:55Maybe it's something from Salesforce.

8:58Or maybe it's Office 365 or some other internet service.

9:02One of the cool things about software-defined wide area

9:04networking is that we can configure rules and performance

9:08standards which will dynamically control which

9:11path we're going to take-- direct internet access going up

9:14through the tunnel or going up through the MPLS network

9:16to our headquarters site and then being routed up

9:18to the internet.

9:19And by performance, I mean we can

9:20look at things such as jitter and delay and packet loss.

9:24And in a Fortinet environment, those

9:26are referred to as SLAs, for Service-Level Agreements.

9:29And then we can have rules that specify, OK, if this user is

9:32going out to a specific application

9:34or a specific service, we only want

9:36to use paths that guarantee a certain level of service

9:39between that client going out to the services.

9:41So perhaps from FortiGate 2's perspective,

9:43our cheapest internet option is ISP A. So perhaps

9:47we specify that we want to go ahead

9:49and use our VPN over service provider

9:52A for our preferred path for that client going

9:54to that specific application on the internet.

9:56However, if there's degradation on that path

9:59or it's not meeting the service-level agreement,

10:01then we can specify in our rules that we

10:02want to go ahead and as a second-place winner regarding

10:05the SLA being met, we want to use the MPLS.

10:08So the traffic would be forwarded over the MPLS network

10:10up to the main site who'd then route it out.

10:12Now, if there was a problem with the MPLS network

10:14or if there's a problem with the headquarters site,

10:16we can also specify, in third place, direct internet access.

10:20And that way, this FortiGate could go ahead

10:22and do direct internet access through the service provider

10:25to allow this client to go ahead and access that application

10:28on the internet.

10:29Again, that could be Salesforce or Office 365

10:32or some other software as a service that

10:33is being used by this customer.

10:35And the cool thing about these rules and these SLAs

10:38is that they're dynamic.

10:39They can monitor the traffic.

10:40And they can look at jitter, delay, and loss, and as

10:43a result, pick the appropriate path to forward the traffic.

10:46So one of the reasons it's called

10:47software-defined wide area networking

10:49is that we're setting up the rules and the policies.

10:52And then based on the conditions, the software

10:54that we configured is going to control

10:57which path we're going to use through the network--

10:59and in this example, based on service-level agreements

11:01being met regarding jitter, delay, and loss.

11:04So with this big-picture overview

11:06regarding SD-WAN in mind, in the next video,

11:08let's turn our attention to the basic infrastructure

11:11that we can use as part of our transport/underlay network

11:15that we can then use as part of our lab.

11:17So I'll see you in the very next video

11:19as we put a lab design together.

11:21Until then, I hope this has been informative,

11:23and I'd like to thank you for viewing.

SD-WAN Lab Design

0:06In this video, you and I get to put a design plan together

0:09for our lab topology.

0:11And for this lab design, I want to focus on

0:13the underlay network here, which can also be referred

0:16to as the transport network.

0:18And so for the lab design, I'd like

0:19to go ahead and use four locations.

0:22And so for the first location let's go ahead

0:24and put a FortiGate here, and let's call this DC

0:27as in Data Center 10.

0:29We'll call that FortiGate DC-10, to remind us

0:31that it's at a data center at location 10.

0:34And let's also create a second one.

0:36We'll call it DC-20.

0:37So there's another little FortiGate right there,

0:39and we'll label that DC-20.

0:42And let's have a couple of remote sites as well.

0:44So let's go ahead and down here let's use site 30,

0:47and that way for me it'll be easier just

0:49to remember 10, 20, 30, and 40.

0:51So let's call this one site-30.

0:54And also at one other remote site

0:56down here, we'll call this site-40.

0:58And each of them have a local network or two attached,

1:02so let's just draw this here to represent that

1:04on each one of those sites.

1:06And while we're at it, let's put in some IP dressing

1:08plans as well.

1:09So the data center 10, let's use 10.10 a 24-bit mask,

1:13and a site-20, let's use 10.20.00, with a 24-bit mask,

1:17and the site-30, we use 10.30.0.0.

1:22And any guesses for site-40?

1:24You got it 10.40.0.0, with a 24-bit mask.

1:29And we'll also put at least one device

1:31that we can work with on each of those networks.

1:34And in the lab environment, I'm going

1:35to need to be able to manage all these.

1:37So I'm going to also put each of these devices

1:39on a little management network, which

1:41I'll just draw right here.

1:42That way, I can locally get to each one of them,

1:44and that management network is my home office network,

1:47which has the 192.168.1 address space.

1:51So let me make a little legend over here for the management

1:53network.

1:54It's the 192.168.1.0, and on that network

1:59I've got my management PC, the one

2:01that we're going to be sitting at to manage these devices.

2:03And I've also got on that management network

2:05a FortiManager that we can also use

2:08if we want to do centralized management of these firewalls.

2:11And let's also go ahead and put some internet connectivity

2:14in here.

2:15So the big cloud represents an internet as a whole,

2:18and let's also identify a few service providers.

2:20So we'll have service provider A,

2:22I'll call it SP.A right there, and service provider B,

2:25and service provider C.

2:27Let's also imagine for our lab environment,

2:29we want to have a separate path using MPLS, Multiple Protocol

2:33Label Switching from a service provider.

2:34So I'll go ahead and put that here MPLS, and for not having

2:38to draw on top of each other, I'll also go ahead and put one

2:41over here as well.

2:43MPLS.

2:44And let's say we're using service provider D for that.

2:47So I'll go ahead and put a D there as well.

2:49And I'll put a D there just to realize

2:50it's the same service provider.

2:52And then for connectivity between the data centers

2:55and the remote sites and the service providers and MPLS,

2:58I'm going to use a lesson my mom taught

2:59me many, many decades ago.

3:02And that is you might want to bring a sweater

3:04or jacket because you can always take it off.

3:06But if you go and you don't have the jacket,

3:08you can't put it on.

3:09And so we may or may not be using all these service

3:12providers and the MPLS from every FortiGate,

3:15but what I want to do is configure

3:17the FortiGate, so they have those connections ready to go.

3:20So if we need them, we can just enable them and be good to go.

3:24So on DC-10, we're going to have A connection out

3:27to service provider A. I'll go ahead and color code that

3:30and to service provider B, I color code that as well.

3:33And service provider C, we'll color code that,

3:35and we'll also have a connection going out to our MPLS provider.

3:40So all of those wide area network options

3:42will be available to DC-10, and we'll

3:44do the same thing for DC-20.

3:45It'll have an MPLS connection to the MPLS network provided

3:49by the service provider, and we'll

3:50have an ISP A connection and an ISP B connection

3:54and an internet service provider C connection as well.

3:57And at the remote site, site-30 and site-40,

4:00it's not likely in a production environment

4:01that we're going to have three different ISPs and an MPLS

4:04connection.

4:05But what I'd like to do in preparation for being

4:07able to use any of these services,

4:09is I'd like to go ahead and also configure site-30 and site-40

4:13with the same connections.

4:14So again, like my mom said, it's not required to use them,

4:17but if you have them, then you can use them if you want.

4:20So I'll put the connection here for service provider A

4:22and service provider B and service provider C,

4:26and the same thing here at site-40, service provider

4:28A in blue, service provider B in pink,

4:32and service provider C in red.

4:34And then the green one represents the connection

4:36to the MPLS service.

4:37So what we're building here or designing

4:39is the underlay or the transport network,

4:41and then once it's in place, and then we

4:43start working with IPsec and sd-wan and the rules

4:46and so forth, we can then steer and control

4:48the traffic over this transport network.

4:51So let me also share with you a few components that we'll

4:53be using to pull all this off.

4:55Starting off, we have some physical firewalls.

4:57And in my lab, I've got a set of 60 fs running

5:01the latest and greatest version as of this recording

5:03of the FortiOS.

5:05To provide the virtualized environments for these PCs that

5:09are going to be connecting and sending traffic

5:11through the Fort gates on the back end,

5:13I'm using ESXi, which is the hypervisor from VMware.

5:17So my management PC right here is going to be physical,

5:20but the FortiManager and these devices

5:22hanging off of these respective networks,

5:24those are all going to be little VMs running as part of VMware.

5:28I also want the ability to go ahead and control the delay

5:31and jitter and packet loss through these various internet

5:35service provider connections.

5:37In my lab environment, what I used to do that was

5:40I used Eve-NG.

5:42And instead of Eve-NG, I've got a switch and also a router,

5:46and I've got four separate links, one

5:48for each of the service providers,

5:50and I've also got one for the MPLS network.

5:52And so in Eve-NG, there's an option

5:54to actually inject jitter and delay and cause

5:57one of these circuits to be less desirable quality-wise

6:00than another.

6:01And that way we can play with that and tweak it,

6:03and I'll show you how I set that up as well,

6:05as we proceed through this set of videos.

6:06So as far as what we need to configure in this topology

6:09to get it all up and running on the FortiGate,

6:11let's go out and do a factory reset.

6:13And that way we know what we're starting with.

6:15Also in these FortiGates, I'd like

6:16to use centralized Source NAT.

6:18So that way we'll have a separate policy.

6:20For Source NAT it won't be integrated

6:22as part of the firewall policy.

6:24And then on these firewalls, we'll

6:26need to carve out the interfaces.

6:27So for simplicity, let's use internal 1.

6:31That's one of the physical interfaces on each

6:33of the FortiGates, and that physical interface

6:35is connected to in my lab environment, a switch

6:38where it's doing trunking.

6:39So on that physical interface, we'll carve that up

6:41for management, meaning we'll give it the 192.168.1 address

6:45space, and for DC-10, let's just use .10 everywhere.

6:48For DC-20, we use .

6:5020.

6:50For site-30, we use .30 and for site-40, we use .40.

6:53And then for all the other interfaces, the local area

6:56network here and the three service providers

6:59and the MPLS connection, on the FortiGate,

7:01we'll just create VLAN interfaces for each of those.

7:03And just a little note for my self, service provider A

7:06is VLAN 23 with the 23.1.2 address space,

7:11service provider B is in my lab environment VLAN 24

7:15with the address space of 24.1.2.0

7:18also with a 24-bit mask.

7:20Service provider C is VLAN 25 with an IP address

7:24space of 25.1.2.0, and last but not least, I've

7:29also set up the MPLS connection in my lab environment,

7:31and that's using VLAN 26 and that address space is 26.1.2.0.

7:38And so the IP address is for each of these service providers

7:40is going to be a .2 on each of these networks.

7:43So for example, service provider A

7:45would be 23.1.2.2 as the next hop

7:49there for that service provider.

7:50So I'll make a note here.

7:51This can be .2 for the last octet

7:53for each of the interfaces on all the service providers.

7:56Also in this underlay or transport network,

7:58if we want traffic to flow through the firewalls,

8:01we are going to need to have some policies,

8:03and because we're using centralized Source NAT,

8:04that would include network address translation, and also

8:07firewall policies for permission.

8:09Another core piece of the infrastructure

8:11is to make sure that routing is in place.

8:13So in our basic infrastructure here,

8:15prior to implementing any type of sd-wan features,

8:18let's just use service provider A as the one

8:21and only next hop our default static route.

8:24So that means that DC-10, DC-20, site-30 and site-40,

8:28just initially, are going to have their next hop as 23.1.2.2

8:34as the next hop for their default route

8:36to get out to the internet.

8:37And then later as we begin to implement

8:39the sd-wan components, we'll set up our sd-wan zones,

8:41include the members, we'll change the routing

8:43at that point.

8:44But for the initial base configuration,

8:46we're going to use service provider

8:47A as the single service provider for all four sites.

8:51So now with our lab design in place,

8:54let's go ahead in the next video,

8:55and let's tackle DC 10 by starting with a factory reset,

8:59and then walking through the steps of setting up

9:01its interfaces, the policies, and the routing

9:04to get DC 10 in our topology.

9:06So we get to do that in the next video, and I'll see you there

9:09in just a moment.

9:10Until then, I hope this has been informative,

9:12and I'd like to thank you for viewing.

Prepping the DC-10 FortiGate

0:00[MUSIC PLAYING]

0:06In our previous video, we put together

0:08a plan for our lab topology.

0:10In this video, we're going to start our configuration

0:12with DC-10.

0:14So as we turn our attention here to DC-10 in our topology,

0:18let's also just do a quick recall of what we need to do.

0:21So we're going to go to factory reset,

0:23enable centralized source NAT, create the interfaces,

0:26set up the policies and the routing

0:28so this PC can get to the internet.

0:29And we're going to leverage service provider a.

0:31So behind me in the rack, I've got a FortiGate model 60F.

0:35And I've also got a computer connected to it

0:37with a console cable.

0:38So from this computer I'm sitting at,

0:40let's RDP over to that device, and via the console cable,

0:44do a factory reset of this firewall in preparation

0:47for setting it up as DC-10.

0:49So here's that firewall.

0:50A few moments ago, I just did an execute factory reset.

0:53I confirmed.

0:54And it has wiped the config.

0:56And it's rebooting as a brand new firewall ready for us

0:59to configure.

1:00All right, so go ahead and log in as admin.

1:02There's no password by default. So we'll set one.

1:05Press Enter.

1:05We'll confirm that password.

1:07Press Enter.

1:08And we are good to go.

1:09So we should also be able to connect on the GUI

1:12to the default IP address on this platform, which is .99.

1:15So if we wanted to confirm the address,

1:17we can do a get system interface.

1:19And press Enter.

1:21And there's the IP address right here.

1:22So this IP address is being used on this logical interface

1:25called internal, which, on this platform,

1:27includes the first five interfaces:

1:29internal 1, 2, 4, and 5, all part

1:32of this logical internal network.

1:34So we should be able to connect to it right here, at this IP

1:36address of 192.168.1.99.

1:38Let's give that a shot.

1:39We'll log in as admin with the password as specified.

1:41And with that password supplied, we'll click on Login.

1:44I'll make this a little bit bigger.

1:45I'll click on Begin.

1:47We'll go ahead and call this DC-10.

1:49So I'll type in DC-10.

1:51Click on OK.

1:53Now, I plan to use Internal 1, that physical interface,

1:56and then on that physical interface,

1:57configure the management IP address.

1:59And then under that physical interface,

2:00set up all the VLAN interfaces as well.

2:03So to do that, I need to go to Network right here

2:06and click on Interfaces.

2:08And go to this Logical Interface called Internal.

2:10And I need to tell it that it doesn't

2:12get all these interfaces.

2:13So I really just need interface 1

2:15not to be part of that internal logical switch.

2:17And in fact, while I'm at it, I'm going to go ahead

2:19and say, I don't need any of these.

2:21Now, I'm currently connected on internal5.

2:23That's physically how I'm currently connected.

2:25So I'm going to go ahead and disconnect that.

2:27And let me go ahead and just tuck in some interface

2:29because it needs some interface there.

2:31I'll give it wan2, which I'm not using.

2:33Now I'll click on OK.

2:34Now, I'm going to lose connectivity here because I

2:36was connected on port 5.

2:37And that is no longer a part of this logical internal interface

2:40with the IP address that I'm currently connected to.

2:42So I'm going to go ahead and close

2:44this browser because that's not going to be too helpful.

2:46Let's go back to the command line.

2:48And let's proceed with some of our initial configuration

2:50there.

2:50So I'll do a config system interface.

2:53And let's go ahead and do a show.

2:54And what we want to do is I want to take this interface right

2:57here, internal 1, which can now be used

2:59as a regular layer 3 routed interface.

3:02And I want to put the IP address of 192.168.1.10

3:06with [INAUDIBLE] on this interface.

3:08So we'll type in edit internal1.

3:10And then we'll do a set ip.

3:12I also just realized that if we try

3:14to put on the IP address of 192.168.1.10,

3:17we've already got an IP address on

3:19the logical internal interface on the 192.168.1 network.

3:22So before I do that, let's go back in.

3:24With config system interface, let's edit internal.

3:28Let's do a quick show.

3:30So there's the IP address.

3:31And what we'll do is a unset of IP.

3:34So now we've just removed the IP address off

3:36that logical internal interface.

3:37So we do a show.

3:39Looks good.

3:39We'll type in end.

3:40Now we can go to internal1 and put an IP address

3:42on that same subnet.

3:44And we'll use .10.

3:45So we'll do a config system interface.

3:48Let's edit internal1.

3:49That's the first physical port.

3:50Let's do a show--

3:52fantastic, and a set ip.

3:54And we want that to be 192.168.1.19

3:57with a 24-bit mask.

3:58And that will be our management interface.

4:00And we also should allow some access.

4:02So let's do a set, allow access.

4:04And let's allow HTTPS and some ping.

4:08And in case I try to connect with HTTP,

4:11I want that to go ahead and redirect over

4:12to [INAUDIBLE],, which it will by default,

4:15as long as I allow HTTP.

4:16Let's also allow SSH.

4:18And we can add more later if we want to.

4:20So let's do a show real quick, verify our settings.

4:22And we'll type in end.

4:23And now we should be able to connect

4:25to this device at that management IP address.

4:27So let's verify that.

4:28We'll bring up a browser.

4:29And I just realized something really important.

4:31And that is, there's no connectivity on port1.

4:34Currently, I have a cable connected to port5, internal5,

4:37on the firewall.

4:39And we just configured internal1.

4:40So let me walk back to the rack.

4:42Let me go ahead and put it in the cable to port1.

4:44And then we'll come back here and check it out.

4:46All right, so I just plugged that in.

4:48So it may take a few seconds on the back end switch

4:50for spanning tree to allow forwarding of traffic

4:52on that port.

4:53And so we'll give that a few moments.

4:55And then we'll go ahead and click on Reload.

4:57And that looks better.

4:58So even though it's a certificate warning,

5:00at least we're connected to that firewall.

5:02And it simply because the CA who issued the certificate

5:05that the firewall is using by default

5:07isn't trusted by my computer-- no worries initially.

5:10So we'll click on Advanced.

5:11And we'll scroll down and click on Proceed.

5:13We'll log in as admin.

5:14We'll specify the password that we set.

5:16Press Enter.

5:17And we are now logged in to DC-10.

5:19So actually, let me go ahead and log out here

5:21now that we have the basic settings up in place.

5:24And I'm going to go ahead and close my remote desktop

5:26session.

5:27And I'll connect from my PC here,

5:29over to 192.168.1.10, which is the physical internal1

5:33interface that we're going to be using for management for DC-10.

5:37So we'll log in from my management PC.

5:39All right, so let's get to configuring.

5:41A couple of things we wanted to set

5:42were, I want to go down to System Settings.

5:44And I want to specify that, for this firewall,

5:46I want to use Centralized Source NAT.

5:48So we'll go ahead and enable that.

5:49I also want to change the timeouts on my lab environment,

5:52so I don't get logged out all the time.

5:54And we'll click on Apply.

5:56And let's go to Network and Interfaces.

5:58So here I have internal1, which has the management IP

6:01address on it.

6:02And let's carve out interfaces that we're

6:04going to use for the network behind DC-10,

6:07the 10-10 network, which we're going to use VLAN 10 for that.

6:10And let's carve out the interfaces

6:11for the three service providers as well as our MPLS service

6:15provider.

6:15So as a reminder, let's take a look at our topology

6:17here on DC-10.

6:18We're going to have connections to service provider A, B,

6:21and C, and also to the MPLS service provider.

6:24So those would be VLANs 23, 24, 25, and 26.

6:28I color-coded them down here.

6:30And those are the appropriate network address spaces.

6:32So when we create those sub-interfaces on DC-10,

6:35for the last octet, we'll use .10 everywhere

6:38on DC-10 for those four network connections.

6:41And for this network up here, north here of DC-10,

6:44that will be VLAN 10 in my environment.

6:46So it looks like we need to carve out five VLAN interfaces,

6:49four for our WAN connectivity going through MPLS and three

6:52service providers, and also one to support this VLAN 10 up

6:56here.

6:57So with that in mind, let's go back to DC-10.

6:59And let's make some VLAN interfaces.

7:01So we're going to be using internal1

7:02as the physical interface.

7:04So we create the VLAN interfaces because internal1 is physically

7:08connected to a switch.

7:09And that switch is doing trunking

7:10for all those other VLANs.

7:12That's what makes this possible.

7:13So internal1 will be the physical interface

7:15used for management.

7:16And the VLAN interfaces will be used for everything else.

7:19So we'll click here on Create New.

7:21From the dropdown, we'll click on Interface.

7:23And let's go ahead and name this VLAN 10.

7:25And the parent interface that's supporting this new VLAN

7:28interface is internal1.

7:29That's where our trunk is.

7:31And the VLAN ID is going to be 10.

7:33And that is going to be a LAN interface.

7:35And the IP address that we're going to use up there is

7:3710.10.0.10 with a 24-bit mask.

7:40And we'll allow PING there.

7:42And let's also enable DHCP services

7:45for clients who connect there.

7:46And let's start at .101 in our pool of addresses.

7:49And then I'm going to scroll down in my lab environment.

7:52I'm also going to set a really short lease.

7:54Now, one of the questions might be, Keith, why in your lab

7:56are you sending your lease time to super low value like 300

7:59seconds?

7:59And the reason is I may change things.

8:01So if I change things up, I don't

8:03want to have a lease that was handed out to a client like two

8:06days ago still hanging around.

8:08I want these devices to actively check and renew their leases

8:11frequently, that way if I make changes,

8:13those changes will be updated and known about sooner

8:16than later on those devices.

8:17That looks great.

8:18So we'll click on OK.

8:19So now under the internal interface, we have VLAN 10.

8:22So now, let's make one for the three service providers,

8:25VLANs 23, 24, 25, and also our MPLS service provider.

8:29So we'll click on Create New.

8:31From the dropdown, we'll click on Interface.

8:33And let's call this ISP_A.

8:36And then just for my own benefit,

8:38I'm going to put VLAN 23.

8:39And that way when I see it, I'll remember exactly what it is

8:42and where it is.

8:43So that's going to be a WAN interface.

8:45And the parent interface for that is internal1.

8:48That's carrying the traffic.

8:49And for the estimated bandwidth, I'm

8:51going to start off with 1,000, and 2,000 for the ISPs,

8:54for upstream and downstream kilobits per second.

8:57And the IP address for VLAN 23, for the service provider A,

9:01is--

9:02let's take a look at our drawing here.

9:04It's going to be 23.1.2.

9:06And on DC-10, that sub-interface, that VLAN

9:08interface, is going to be .10.

9:10So here, for the IP address, it will be

9:1223.1.2.10 with a 24-bit mask.

9:15And we'll go ahead and allow a PING on that interface.

9:18And that looks good.

9:19So we'll go ahead and click on OK.

9:21Oh, and I forgot to put the VLAN ID.

9:23It says VLAN 23.

9:24So we'll add that.

9:25Then we'll click OK.

9:26And now we have our first service provider.

9:29So we'll simply repeat that for our service provider

9:32B and C using their respective network

9:35address spaces of 24 and 25.

9:37So we'll click on Create New.

9:39From the dropdown, we'll click on Interface.

9:41We'll name this ISP_v24.

9:45And the parent interface is internal1.

9:47And the VLAN ID is 24.

9:50It's a WAN interface.

9:51And its IP address is going to be

9:5324.1.2.10 with a 24-bit mask.

9:57And we'll enable PING on that interface-- very good

9:59for connectivity testing.

10:00And we'll click on OK.

10:02All right, let's do the third service provider,

10:04service provider c.

10:06By clicking on Create New, from the dropdown, clicking

10:08on Interface, we'll call this ISP_C_v25.

10:15The physical interface is internal1.

10:17And the VLAN ID is 25.

10:20And that is a WAN interface.

10:21And its IP address is going to be

10:2325.1.2.10 with a 24-bit mask.

10:27And we'll allow PING on that as well.

10:28And click on OK.

10:29So let's check our work.

10:30I've got service provider A, B, and C.

10:32They're on VLANs 23, 24, 25.

10:34And the address space is 23, 24, 25.

10:37That all looks great.

10:38Let's add one more for the connection to our MPLS service

10:41provider.

10:42So we'll click here on Create New--

10:43Interface.

10:44And let's call this MPLS_vlan26.

10:49And the parent interface is internal1.

10:51And the VLAN ID for that in my lab environment is 26.

10:55And it also is a WAN interface.

10:57And its IP address is going to be 26.1.2.10 here on DC-10

11:02with a 24-bit mask.

11:04We'll allow PING there as well.

11:05And click on OK.

11:06So let me just check our work here real quick.

11:08And that looks great.

11:09So we have our VLAN interface for our internal network

11:12behind DC-10.

11:13And we have our three service providers.

11:15And we have the MPLS connection as well.

11:17So if we take a look at our checklist,

11:19what is next on DC-10?

11:21So we enabled Centralized Source NAT.

11:23We carved out our interfaces.

11:24Next, we need policies for network address translation

11:27and also for permissions for traffic from that 1010 network

11:31to go out to the internet.

11:33So let's set up our NAT and firewall policies next here

11:36on DC-10.

11:37So to do that, we'll go ahead and collapse Network.

11:40Go to Policy and Objects.

11:41Let's start with our Centralized Source

11:43NAT by clicking here on Central Source NAT.

11:45And click on Create New.

11:47And the incoming interface is going

11:49to be traffic coming in on the VLAN 10 interface.

11:51And for the outgoing interface, initially,

11:53for our basic config, let's just use Service Provider A.

11:57And then we'll tweak and modify that as we

11:58build our [INAUDIBLE] together.

12:00So for the moment, it'll be Service Provider A

12:03and the source address.

12:04Let's lock that down to just VLAN 10 traffic.

12:06So here's an address object for that right here.

12:08So we'll select that.

12:09And for the destination for the NAT policy,

12:12they can be going anywhere-- fantastic.

12:14And effectively, that's going to do port address translation,

12:16mapping clients source IP addresses to whatever it

12:19happens to be on that external or egress interface, which

12:22is 23.1.2.10 here, through service provider A.

12:26So we'll click on OK.

12:27So now we have our NAT policy.

12:29Let's go ahead and set up permissions with our firewall

12:30policy.

12:31Also, what I love to do here in our firewall policy

12:34is I like to go ahead to the Implicit Deny.

12:36And in my lab environment, I'm going

12:38to say Log all IPv4 Violation Traffic.

12:40That way, we have nice clean logs of everything

12:42that's going on.

12:43And that's really helpful for initial troubleshooting.

12:45So we'll click on OK.

12:46I'm going to take this fun rule right here from internal

12:49to Lan1.

12:50I'm going to right click and delete that.

12:51We don't need that.

12:52Click on OK.

12:53And let's create another policy that allows traffic from VLAN

12:5610 to go out to the internet.

12:58So we'll click here on Create New.

13:00Let's call it VLAN 10 to Outside.

13:02And the incoming interface would be our VLAN 10 interface.

13:06So we'll select that.

13:07The outgoing interface in our current topology

13:09is going to be just Service Provider A.

13:12The source IP address space is going to be the 10.10.0

13:15network.

13:16So there's an address object for that right here.

13:18So we'll go ahead and choose that address object.

13:20And the destination could be anywhere

13:22because the internet's a big place.

13:24So we'll say, All There.

13:25And regarding what protocols or services they could use,

13:28I'm going to leave it wide open there as well.

13:30The action is Accept or Permit.

13:31And by default, it's flow-based, which is fine.

13:35And the one other change I'd like to make here

13:37is I'd like to log in All Sessions.

13:39Again, that's helpful in a lab for troubleshooting.

13:41And we'll click on OK.

13:42All right, so we have our new policy in place.

13:45And for the last piece here, we also need to set up routing

13:47because unless Firewall 10 believes that it should forward

13:51traffic out through Service Provider A, it won't.

13:54And so if we want our NAT policy and our firewall policy

13:57to be effective and be used, we also

13:59need to have routing in place.

14:01So let's set up a static default route here on DC-10 that says,

14:04hey, your default route should use the next hop of 23.1.2.2,

14:09which is Service Provider A. So back at DC-10,

14:12let's go back up to Network.

14:14And from the Network section, we'll go to Static Routes

14:17right there.

14:17And with Static Routes selected, let's

14:20add a new default static route that's

14:22going to use Service Provider A the next hop address there.

14:25So we'll click on Create New.

14:27And the Gateway Address is--

14:29on Service Provider A is going to be 23.1.2.2

14:32And if we press Tab, it's automatically

14:34going to select the egress interface.

14:36And that's because the next hop address here, 23.1.2.2,

14:39is on the same exact subnet as this interface ISP A_v23.

14:45And that's why it auto-populated for us.

14:47We'll leave everything else, including

14:48the administrative distance, at their defaults.

14:50And click on OK.

14:51So let's make sure we have all the pieces in place

14:53here on DC-10.

14:54We have the intro one, physical interface,

14:57that's connected over to a physical switch with trunking.

15:00So that physical interface is being used for our management

15:02interface at 192.168.1.10.

15:05That's how we're currently connected to DC-10.

15:08And then beneath that, we carved out logical VLAN interfaces

15:12for each of these service providers and also one

15:14for VLAN 10.

15:15We also set up the Source NAT policy and also

15:18the firewall policy to allow the traffic from VLAN 10

15:21to go out to the internet through Service Provider A.

15:23And we also put the routing in place

15:26with a static default route telling DC-10,

15:28hey, if you ever need to forward traffic to a route

15:30that you don't know about, go ahead and use Service Provider

15:33A's next hop address at 23.1.2.2.

15:37So with all of that in place, what's left?

15:39Well, we should probably test it.

15:41So that's what you and I get to do in the very next video is

15:44verify our connectivity and do any troubleshooting

15:46if necessary for the basic infrastructure

15:49of this underlay network.

15:50So I'll see you in the next video in just a moment.

15:53Until then, I hope this has been informative.

15:55And I'd like to thank you for viewing.

Test and Verify DC-10

0:00[INTRO MUSIC]

0:06Now with DC-10 configured, I want to take a moment in this

0:09video just to verify that traffic can actually flow from

0:13devices in VLAN-10 out to the internet using service provider

0:17A. So in a moment, let's put a client here on this network

0:20and test and verify that the client here on 10.10 can

0:23actually get out to the internet via service provider A.

0:25But even before we bring a client,

0:28there's also a test we can do right here at the FortiGate

0:30just to verify basic connectivity.

0:32So let's do that first.

0:33So here at that DC-10.

0:35This is a SSH session I have over to the Management IP

0:38address on DC-10 at 192.168.1.10.

0:42And so from here, what we could do

0:43is we could try to ping each of our service providers.

0:46And so just basic connectivity testing would be great.

0:48So let's go and do that.

0:49Let's do a ping to 23.1.2.2 press Enter.

0:53[LAUGHTER]

0:56I'm so excited about the ping, I forgot the execute.

0:58So execute ping to 23.1.2.2 press Enter.

1:03OK, that works, fantastic.

1:04So here from DC-10, we could also

1:06execute ping to www.fortinet.com.

1:10So what that's going to do, is going to go ahead

1:12and use DNS on the outside world.

1:14So that alone is verifying connectivity.

1:16And if the pings are then successful,

1:18that also means our traffic is being forwarded out

1:20through service provider A because that's

1:21where our default route is.

1:22So we'll press Enter.

1:23And that is working.

1:25Looks great.

1:26So we do a get, router, info, routing-table,

1:30and let's go ahead and do all and press Enter.

1:32There's our default route going through service provider A.

1:35And that's what's providing us connectivity

1:37to the outside world.

1:38So the final test here would be to bring up a PC here

1:41on VLAN 10 and verify that computer, by using the Central

1:45Source NAT and firewall policies,

1:46also can get access out to the public internet.

1:49So here's my ESXi host, which behind the scenes

1:52is providing a lot of this virtualization.

1:53And let's go down to Networking.

1:55And let's go down to my port group for VLAN 10.

1:59So as far as which devices, I've actually

2:00got a Windows 11 computer that's currently on VLAN 10.

2:04Let's use it.

2:04It's sitting there.

2:05So we'll go ahead and power it up.

2:06And I'll also go ahead and open up a console to that device.

2:09So go ahead and open a remote console.

2:11And we'll give that about a minute and a half to boot up.

2:14And as that power is up, that represents this little computer

2:16right here on the 10.10 network.

2:18So I'm going to go ahead and bring it over.

2:20So here it is let me go ahead and log in.

2:23So here on the client list, lets do an IP config just

2:25to verify our IP addressing.

2:26So we're on the 10.10.0 network.

2:28Our host address is 101, assigned via DHCP.

2:31In fact, we can confirm that with an IP config.

2:33So a dash all or slash all, either way is great.

2:36So the IP ipconfig/all shows us additional details,

2:39including our DHCP server address and our DNS servers.

2:43So from here, if we did a ping out

2:45to www.fortinet.com and press Enter, that looks pretty good.

2:49So we have name resolution that's working, fantastic.

2:52And we also have four out of four pings

2:54that were successful going out to the internet

2:56through the firewall.

2:57So let me go ahead and minimize our client.

2:59So in this video, we verified a path

3:01from DC-10 to the internet through service provider A.

3:04And then, leveraging the policies, including source NAT

3:07and firewall policies.

3:08We also verify that this client has access out

3:11to the public internet.

3:12So now the DC-10 is all set up.

3:14We're going to do the same exact process on DC-20 and also

3:18site-30 and site-40 with the exception of changing

3:21the last octet for each of their individual IP addresses.

3:24But the process of the VLAN interfaces

3:26and the NAT policy and the firewall policy

3:29is all the same.

3:30So I'll do those three in the background to get them ready.

3:33So in the next video, let's turn our attention

3:35to behind the scenes.

3:37What I'm going to be doing that's

3:38going to be able to help us influence the traffic

3:40flow through the network.

3:42And that's going to leverage on the back end, a little software

3:45application to have running called Eve-NG.

3:47And we'll take a look at how that's all

3:49put together in the next video.

3:51So I'll see you there in just a moment.

3:52Until then, I hope this has been informative,

3:55and I'd like to thank you for viewing.

Behind the Curtain

0:06When designing and putting together this lab,

0:08I thought to myself, self, wouldn't it

0:10be great if we could influence, in our lab environment,

0:13if we could influence the links for the various service

0:15providers?

0:16For example, maybe adding 100 milliseconds of delay

0:18through service provider A or adding

0:20some packet loss, a little bit, not a whole bunch,

0:22but a little bit through service provider B,

0:24or setting up additional jitter through service provider C.

0:27So to do that, I had to get a little bit creative.

0:30And in this video, I'd like to walk you

0:32through behind the scenes with exactly what I did.

0:35So let me start by drawing out our ESXi hypervisor

0:38that I'm using.

0:39So I'm using one of my servers.

0:41It's ESXi three.

0:42It's a Dell rack server.

0:44So I'll label that right here, ESXi.

0:46That's from VMware.

0:47So I've got a couple of virtual switches

0:49that are in play inside of the ESXi hypervisor.

0:52So let me go ahead and draw those out right here.

0:54There's one of our virtual switches.

0:56And let's call that vSwitch A. And we'll

0:59call this other one vSwitch B.

1:01And think of these virtual switches

1:03as just a logical layer two switch with the ability

1:06to carve out VLANs.

1:07And the mechanism that is used to carve out individual VLANs

1:11and then assign VMs to them is the use of port groups.

1:14So I'm going to go ahead and just jot out PG just

1:16to remind us that, inside of each of these switches,

1:19there is one or more port groups.

1:21So on this switch, I made a poor group for VLAN 10.

1:24So I'll go ahead and put V10 there.

1:25So once we have this port group set up,

1:27if we want to spin up a new VM like this one

1:29right here that's sitting currently in VLAN 10,

1:31to put them in VLAN 10, we take this network interface card

1:34for that VM.

1:35And we'd associate it with this port group that's in VLAN 10.

1:38And poof.

1:39That little machine is now in VLAN 10.

1:41So I'll go ahead and draw that little VM connected here.

1:43And this is a little computer at 10.10.0.0101.

1:48It got the first IP address handed out from the DHCP pool.

1:51And then on this virtual switch inside the ESXi host,

1:53I also created individual port groups

1:56for each of these service provider networks.

1:58So that would include a port group for VLAN 23

2:01going through service provider A and a port group

2:04for service provider B, which is VLAN 24,

2:07and a port group associated with VLAN 25.

2:11And I also created a port group to support VLAN 26, which

2:14is going to be used for MPLS.

2:15And over here on switch B, I have just one port group that

2:19is supporting the native VLAN.

2:21It says VLAN one.

2:22But there's no tagging involved.

2:23It's just like normal native traffic without any 802.1Q

2:26tagging at all.

2:27And that represents my home network of 192.168.1

2:32with a 24-bit mask.

2:33And because there's interaction between the devices

2:36in this virtualized switch environment

2:37and the physical world, let me also

2:39go ahead and share with you a couple of physical switches

2:42I have here in my home office.

2:44So there's one switch.

2:45And here is another switch.

2:47And I'll label those as physical switch A and physical switch B.

2:53And the connection between these virtual switches

2:55and the physical switches are through physical network

2:59interface cards on the ESXi host.

3:01And logically, I've got one connection

3:03that goes from this virtual switch

3:04out to the physical world.

3:06And that's using a network interface

3:08referred to as a VMNIC in the world of VMware ESXi.

3:12And then I've got a separate VMNIC

3:13that's supporting any connections

3:15from this virtual switch out to this physical switch.

3:18So this may be VMNIC 0.

3:20And this one may be VMNIC one.

3:21And they're connected to ports down here

3:23on the physical switches.

3:25And on switch A, this port is configured as a trunk.

3:28Meaning it can do 802.1Q tagging as it sends frames for specific

3:32VLANs.

3:33And it receives frames with 802.1Q tagging.

3:36It knows how to process those as well.

3:38And then over here on physical switch B,

3:39because I'm not using any trunking up here,

3:42I'm not doing any trucking down at this physical switch either.

3:44So this physical switch and this virtual switch

3:47are just carrying the basic VLAN one traffic, nontagged.

3:51And also to make this picture complete,

3:52I also have a connection between these two physical switches

3:56that allows the VLAN one traffic to go ahead and go across.

3:59So it's not trunking all the VLAN traffic from this switch

4:02over to this one, but it does allow VLAN one traffic

4:04between the two virtual switches based

4:06on this physical connection here in the physical world.

4:09So let's bring in a FortiGate, a physical FortiGate.

4:11This will represent the one that we configured

4:12a couple of videos ago.

4:13So I'll draw that right here.

4:15And that physical FortiGate has a physical connection

4:18into a physical switch.

4:19And let's go ahead and put it on this port right

4:21here on physical switch A. And this port is also

4:24configured as a trunk port.

4:26And on the FortiGate, I'm using the physical interface internal

4:29one.

4:30So on that internal one interface,

4:32I have the IP address of 192.168.1.

4:35And on DC 10, it would be .10 on my management network.

4:38And then leveraging that physical interface,

4:40I then created the VLAN interfaces

4:42for all the other VLANs, including an interface

4:44for VLAN 10 and one for VLAN 23 and one for VLAN 24 and one

4:50for VLAN 25 and one for VLAN 26.

4:54So the little virtual machine that we

4:56plug into this port group for VLAN 10

4:58is logically on the same network as this VLAN 10 interface

5:02over here on the FortiGate.

5:04Next, let's chat about we can route on this

5:06FortiGate out to the physical world using service provider

5:09one.

5:10Currently, this FortiGate, DC 10,

5:12has a default route with the next hop of 23.1.2.2,

5:16which is our ISP's address up here in the service provider

5:20network.

5:20So where is that next hop address in our topology?

5:22Well, that's a little router, a little virtual router

5:25right here in my virtualized environment

5:27that is connected with one interface

5:29to the port group of VLAN 23.

5:32So here's our router for internet service provider A.

5:35And Its other interface, I placed here on switch

5:38B, which is going to the native VLAN.

5:40And then in addition on this router,

5:41I set up network address translation.

5:43So it takes all the traffic coming

5:45in that source from the 23 address space

5:48and nets it out on this interface,

5:49which has a 192.168 address.

5:51And then on my physical network, I've

5:53got a router at .1 that is once again also doing

5:56network address translation before forwarding that traffic

5:59out to the real internet.

6:00So all that was well and good until I thought to myself,

6:03you know what?

6:03I want the ability to go ahead and modify the quality

6:07of the service prior links.

6:08So if service provider A or B or C

6:10is having like excessive delay or excessive jitter

6:14or a whole bunch of packet loss, how do I simulate that?

6:17And the answer is to integrate an additional virtual machine.

6:20So let me clean up this internet ISP router for a moment.

6:24And let me introduce a new virtual machine.

6:27And that virtual machine is EVE-NG.

6:30EVE-NG is a network emulation tool.

6:33And so in EVE-NG, we can run devices

6:35like Palo Alto firewalls, checkpoint firewalls,

6:38FortiGate firewalls, Juniper firewalls, et cetera.

6:42So inside of this VM called EVE-NG,

6:45I have yet another router.

6:47And let's go ahead and call this R2.

6:48And inside of EVE-NG, which is now

6:51running this little virtualized router,

6:52I have associated that router with its interfaces

6:55here in VLAN 23 and here in VLAN 24 and here in VLAN 25.

7:01So it has three logical interfaces.

7:03Now, the benefit of doing that is

7:04that in EVE-NG, we can go to any one of those links,

7:07and we can specify the quality of that link.

7:10We can introduce delay or jitter or packet loss real time.

7:14And that's the benefit of adding this additional complexity

7:16of adding an EVE-NG machine and associating it

7:19with those three networks.

7:21And then for routing traffic out to the real internet,

7:23it also has a connection here to my 192.168.1 network

7:27and that port group on the second virtual switch.

7:29And once again, router two is doing network address

7:32translation, so that any packets coming in from IP

7:35addresses in this source address space of 23, 24,

7:37or 25 will be netted out to this IP address

7:41on the 192.168.1 network and then forwarded down

7:43to the real router, which is a .1, who, once again, is doing

7:47network address translation before forwarding that traffic

7:49out to the public internet.

7:51So let's take a look at EVE-NG and this little router

7:54R2 that's currently running and its connectivity to these three

7:57networks and also its connectivity

7:59out to the 192.168.1 network.

8:01And behind the scenes, this EVE-NG

8:03is running as a virtual machine inside the ESXi hypervisor.

8:07So here in ESXi, here is the EVE-NG machine.

8:10And if we look at its network configuration,

8:12it has one interface that's connected to my management

8:15network.

8:16And then it has four more network interfaces

8:18that are connected to the logical port groups

8:21representing VLANs 23, 24, 25, and 26.

8:24So for the lab environment, I'm only connecting and using

8:27VLANs 23, 24, and 25 from this router that's

8:31running inside of EVE-NG.

8:32So inside of that VM EVE-NG, this

8:35is the graphical user interface connected to that VM.

8:38So inside that VM, I'm running this virtual router, R2.

8:42And it has three interfaces.

8:44And on those three interfaces, I have IP addresses

8:46configured for the 23.1.2, 24.1.2, and 25.1.2 networks

8:51with .2 being the last octet for each of them.

8:54So that way, our FortiGates, when

8:56they're pointing to the ISPs for A, B, or C,

8:59if they use the next hop of .2 effectively,

9:02they're going to be using this router as their next hop

9:04address.

9:05And then here, EVE-NG, I've got three clouds

9:07that represent those three network interface cards that

9:10are directly connected to the port groups representing

9:13VLAN 23, VLAN 24, and VLAN 25.

9:16So this router is performing network address translation.

9:19It also has a static default route going out to the next hop

9:22address at 192.168.1.2.

9:25And that router at .1, as I mentioned,

9:27is also doing address translation

9:29before forwarding that traffic out to the public internet.

9:31And the whole reason I added this additional layer

9:34was because I want the ability to influence the quality

9:37through service provider A, service provider B, and service

9:40provider C. So if we bring out a client, so this represents

9:42a PC sitting up in VLAN 10.

9:45It's a little virtual machine.

9:46If we do an IP config, we can confirm its address.

9:48It's at 10.10.0.101.

9:50So this PC is using DC 10 as its default gateway.

9:54And DC 10 currently has a static default route

9:57with the next hop of 23.1.2.2, which

10:00is R2's interface on gig 0/1 on VLAN 23.

10:05So if we were to do a trace, so we'll do a traceroute -d for

10:08don't bother doing name resolution.

10:10And let's do a trace out to 8.8.8.8.

10:12What we should see is that the first hop in this path should

10:15be the FortiGate at 10.10.0.10.

10:17And then the next hop should be R2's interface right here,

10:20which is at 23.1.2.2.

10:23And then the next hop beyond that

10:24would be my other internal router here at my home.

10:27With an IP address of 192.168.1.

10:29And then after that, it goes out through the real service

10:32provider network out to the final destination

10:34through the internet.

10:35So let's give that a test by pressing Enter.

10:37And here we go.

10:38So the first hop is the FortiGate DC 10.

10:41The next hop is this router at 23.1.2.2.

10:44Then it goes out to my other external router

10:46here at my home, which is 192.168.1.1.

10:49And then it hits the service provider network.

10:51And then off to the rest of the internet.

10:53So the delay here was all under 20 milliseconds.

10:56So what we could do here in EVE-NG

10:58is we could take this link, and we could right

11:00click on it, and.

11:01And the dropdown, we could click right here on edit quality

11:03and down here, we could introduce delay

11:06and/or jitter and/or loss as part of that connection.

11:10So let's go ahead and, as an easy test,

11:12let's add 100 milliseconds of delay.

11:15So EVE-NG is going to artificially inject

11:18that delay on all traffic that's going

11:20over this link between VLAN 23 and the interface here on R2.

11:26So let's bring back our client and test it.

11:28My hands never left my arms.

11:30We'll go ahead and hit the up arrow key, press Enter.

11:32And what we should expect to see is

11:34that once we start crossing that link now

11:36the delay is over 100 milliseconds for each

11:39and every one of them.

11:40So we'll let.

11:40That complete.

11:41And then also as a test, let's go ahead and set it to 50.

11:45I just want to see how accurate is.

11:47Still, serve me as well.

11:48So let's go ahead and click on Apply

11:50and bring back the client.

11:51So now the delay should be increased by 50.

11:53So we'll hit the up arrow key, press Enter.

11:55And here, we go there we go 53, 55, 60, 62, et cetera.

12:00And that looks great.

12:02So the beautiful thing is we can manipulate these values

12:04of delay and jitter and loss.

12:06And then we can see, in real time,

12:08how SDWAN and the rules that we have set up

12:11adjusts to the traffic flow based

12:13on the rules we have in place.

12:14So my friend, the cat is out of the bag.

12:16This is the detail on how we're going

12:18to inject delay and jitter and packet loss

12:22as part of testing and working with SDWAN.

12:24So thanks for joining me in this set of videos as we've

12:27set up a basic foundation for an SDWAN lab.

12:29And I'll see you, my friend, in the very next set

12:32of videos very, very soon.

12:33Until then, I hope this has been informative,

12:36and I'd like to thank you for viewing.

Team training path

Turn this skill into assignable team training

This free skill is a preview of the courses your team can assign, track, and report on with CBT Nuggets.

What's next?

Ready to keep going?

For your team

Bring this training to your team

See how CBT Nuggets helps IT teams close skills gaps, hit compliance targets, and prove training ROI.

Book a Demo
Just need Fortinet NSE 7?

Learning on your own? Browse individual plans ($49/month, billed annually)

Not ready to buy?
with no purchase required. Already have an account?
Book a Demo