Skip to main content
When Aviatrix deploys a firewall in Azure through FireNet, it adds Network Security Group (NSG) rules on the firewall’s management interface that allow inbound traffic only from the Aviatrix Controller IP. This replaces the open 0.0.0.0/0 inbound rules used in earlier releases. The same protection has been available for AWS FireNet since 8.x. Release 9.0 extends it to Azure. Egress and LAN interface NSGs are not affected; they keep their existing rules so data-plane traffic continues to flow.

How It Works

When a firewall instance is launched, Aviatrix adds inbound NSG rules on the management interface scoped to the current Controller IP. The exact rules depend on the firewall vendor. If the Controller IP changes (for example, after backup/restore or IP migration), Aviatrix updates the source IP on every controller-scoped NSG rule on existing Azure firewall instances.

NSG Rules by Vendor

Palo Alto Networks

Palo Alto Networks firewalls have a dedicated management interface, separate from the egress and LAN interfaces. Management NSG (<instance-name>-management):
The TCP 3978 rule is a placeholder for Panorama connectivity. Its source IP is initially set to the Controller IP. If you use Panorama, update the source to your Panorama server IP.
Egress NSG (<instance-name>-egress) and LAN NSG (<instance-name>-lan) are unchanged.

Check Point

Check Point firewalls share a single interface for egress and management traffic. Egress NSG (<instance-name>-egress): LAN NSG (<instance-name>-lan) is unchanged.

Fortinet

Fortinet firewalls share a single interface for egress and management traffic. Egress NSG (<instance-name>-egress): LAN NSG (<instance-name>-lan) is unchanged.

Behavior on Controller IP Change

When the Controller IP changes, Aviatrix updates the affected NSG rules on existing firewall instances:

Limitations

  • The Panorama placeholder rule (TCP 3978) starts with the Controller IP as the source. If you use Panorama, update the source to your Panorama server IP.
  • Firewall instances launched before this feature was introduced keep their original NSG rules in addition to the new controller-scoped rules.