如何在Terraform中配置Azure FortiGate连接FortiManager?
配置FortiGate连接FortiManager的Terraform方案
核心原理
手动部署时的FortiManager配置项,本质是通过初始化脚本注入FortiGate的CLI配置。在Terraform中可以通过custom_data字段传递该初始化脚本,脚本会在VM启动时自动执行,完成FortiManager的连接配置。
修改后的Terraform代码
resource "azurerm_linux_virtual_machine" "fgtvm" { name = var.fgt.name resource_group_name = var.rg_name location = var.location vm_size = var.fgt.size zones = var.fgt.zones admin_username = "adminuser" admin_password = "123password" # 建议改用Azure Key Vault存储敏感密码,避免硬编码 network_interface_id = azurerm_network_interface.fgt_nic.id storage_image_reference { publisher = var.fgt.image.publisher offer = var.fgt.image.offer sku = var.fgt.image.sku version = var.fgt.image.version } plan { name = var.fgt.image.sku publisher = var.fgt.image.publisher product = var.fgt.image.offer } # 添加FortiManager连接配置的自定义数据 custom_data = base64encode(<<-EOF config system central-management set type fortimanager set fmg <FORTIMANAGER_IP> set serial-number <FORTIMANAGER_SERIAL> set include-default-servers disable end # 可选:配置管理接口允许FortiManager访问(根据实际接口调整) config system interface edit "port1" set allowaccess ping https ssh http fgfm next end EOF ) os_disk { caching = var.fgt.os_disk.caching storage_account_type = var.fgt.os_disk.storage_account_type } }
关键配置说明
- 替换
<FORTIMANAGER_IP>为你的FortiManager实例的公网/内网IP地址 - 替换
<FORTIMANAGER_SERIAL>为FortiManager的官方序列号 custom_data必须经过Base64编码,Terraform的base64encode函数会自动完成编码处理- 接口配置部分的
port1需替换为你的FortiGate实际管理接口名称,确保开启fgfm(FortiGate管理协议)访问权限 - 硬编码密码存在安全风险,生产环境建议通过
azurerm_key_vault_secret读取敏感凭证
内容的提问来源于stack exchange,提问作者Tyra
相关产品推荐
相关产品推荐

