Use Fortigate Nextgent firewall vm to Protect AKS

Thanakrit Rungchatkamol 1 Reputation point
2021-04-25T13:49:09.207+00:00

Hi All,

Can help suggestion me for implement following reference solution architecture below?

90959-2021-04-25-20-40-05.jpg

i want to use Application gateway WAF v2 recieve traffic from internat and then snat to Fortogate firewall and dnat to AKS and Web App service.

it possible to implement? Who can give advice about this solution work with Fortigate and AKS.

BR,
Thanakrit

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
1,006 questions
Azure Web Application Firewall
Azure Kubernetes Service (AKS)
Azure Kubernetes Service (AKS)
An Azure service that provides serverless Kubernetes, an integrated continuous integration and continuous delivery experience, and enterprise-grade security and governance.
1,977 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. msrini-MSFT 9,271 Reputation points Microsoft Employee
    2021-05-07T19:45:23.31+00:00

    Hi,

    If you add the Fortigate as the backend pool of the Application Gateway, then Fortigate needs to act as another reverse proxy. There are timeouts in Application gateway where few flows may get timed out and cause issues.

    When you have Application gateway with WAF why do you need to send the traffic via another firewall which introduces another hop and also does the same security functionality as that of AppGw.

    I would suggest you to redesign your architecture, but if you want to use Fortigate, then you need to fall back to the AppGW V1 SKU and use AKS as the backend where you can add UDR on the gateway subnet and route the traffic via Fortigate. But adding UDR on the gateway subnet is not supported by AppGW V2 SKU.

    0 comments No comments