Requirements for Deep Visibility and Enforcement
The Security > AgentGuard > AI Traffic Flows page displays data only after all of the following conditions are met:- Egress is enabled.
- A WebGroup policy rule has AI Inspection enabled.
- For HTTPS traffic, TLS Decryption is also enabled.

Prerequisites
- AgentGuard setup is complete: your AWS account shows Status = UP and your workloads appear under Cloud Resources > Cloud Assets.
Step 1: Onboard Your VPC
Onboarding a VPC enables Aviatrix to inspect the VPC and your Kubernetes workloads, and to resolve workloads to names rather than IP addresses. Onboarding a VPC automatically creates a High-Availability (HA) gateway pair.
Open the VPCs list
Confirm that the VPCs are discovered
Onboard the VPC
Step 2: Enable Egress
Egress routes the VPC’s outbound traffic through the Aviatrix gateway.
Enable egress for the VPC
Wait for egress to be enabled
Send a test call
api.anthropic.com — and
confirm that it returns HTTP 200. Pod settings do not change.Step 3: Create Your Groups

Create a SmartGroup for your agents
Agents, and match the label
ai-type=llm-client. Matching pods join the group automatically. For the
complete procedure, see
Create SmartGroups.Use the built-in WebGroups for AI providers
avx-ai-* WebGroups (for OpenAI,
Anthropic, AWS, Google, and others). These WebGroups require no additional
configuration.Create WebGroups for your own destinations
Step 4: Create the Policy

Create the block rule
Create the monitor rule
Create the allow-and-inspect rule
Create the east-west rule
Verify the policy order
Step 5: Trust the Certificate
TLS inspection decrypts HTTPS calls of your pods, so the pods must trust the Aviatrix certificate authority (CA). Without the CA, pods report TLS certificate errors after AI Inspection is enabled.
Download the CA bundle
Create a Kubernetes secret
Mount the secret in your pods
Test a call from a pod
curl https://api.anthropic.com returns HTTP
200 with no TLS errors.Step 6: Review the Traffic

Open the Flows list
Review both directions of traffic
Open the Map
Open the Overview dashboard
Troubleshooting
The test call does not return HTTP 200
The test call does not return HTTP 200
No gateway was created
No gateway was created
The AI Traffic Flows page stays empty
The AI Traffic Flows page stays empty
Flows show IP addresses instead of workload names
Flows show IP addresses instead of workload names
Pods report TLS certificate errors after AI Inspection is enabled
Pods report TLS certificate errors after AI Inspection is enabled
unable to get local issuer certificate even with the CA installed,
re-download the current CA bundle from Security > DCF > Settings rather
than reusing a previously saved certificate file — an outdated or
incomplete certificate produces this exact error.Flow details are missing fields, such as URL path or model
Flow details are missing fields, such as URL path or model
A rule you expect to allow traffic is blocking it instead
A rule you expect to allow traffic is blocking it instead