Autoscale Reference

Detailed explanations of autoscale template components, configuration options, and architectural considerations.

Tip

New to FortiGate AWS deployments? Start with the Getting Started guide to deploy your first environment using the Web UI. Return here for deeper architectural understanding.

What You’ll Learn

This section covers the major architectural elements available in the autoscale_template:

  • Internet Egress Options: Choose between EIP or NAT Gateway architectures
  • Firewall Architecture: Understand 1-ARM vs 2-ARM configurations
  • Management Isolation: Configure dedicated management ENI and VPC options
  • Licensing: Manage BYOL licenses and integrate FortiFlex API
  • FortiManager Integration: Enable centralized management and policy orchestration
  • Capacity Planning: Configure autoscale group sizing and scaling strategies (AutoScale only)
  • Primary Protection: Implement scale-in protection for configuration stability (AutoScale only)
  • Additional Options: Fine-tune instance specifications and advanced settings

Each component page includes:

  • Configuration examples
  • Architecture diagrams
  • Best practices
  • Troubleshooting guidance
  • Use case recommendations

Deployment Mode Comparison

Componentautoscale_templateha_pair
Internet EgressEIP or NAT GatewayCluster EIP (moves on failover)
Firewall Architecture1-ARM or 2-ARM2-ARM (4 interfaces)
ManagementStandard, ENI, or VPCDedicated management interface (Port4)
LicensingBYOL, PAYG, FortiFlexBYOL or PAYG (no FortiFlex)
FortiManagerOptional integrationOptional integration
ScalingAuto scales 2-10+Fixed 2 instances (Primary/Secondary)
FailoverGWLB health checksFGCP Active-Passive with session sync

Select a component from the navigation menu to learn more about specific autoscale_template configuration options.