0.0.0.0/0 inbound rules used in earlier releases.
The same protection has been available for AWS FireNet since 8.x. Release 9.0
extends it to Azure. Egress and LAN interface NSGs are not affected; they keep
their existing rules so data-plane traffic continues to flow.
How It Works
When a firewall instance is launched, Aviatrix adds inbound NSG rules on the management interface scoped to the current Controller IP. The exact rules depend on the firewall vendor. If the Controller IP changes (for example, after backup/restore or IP migration), Aviatrix updates the source IP on every controller-scoped NSG rule on existing Azure firewall instances.NSG Rules by Vendor
Palo Alto Networks
Palo Alto Networks firewalls have a dedicated management interface, separate from the egress and LAN interfaces. Management NSG (<instance-name>-management):
The TCP 3978 rule is a placeholder for Panorama connectivity. Its source IP is
initially set to the Controller IP. If you use Panorama, update the source to
your Panorama server IP.
<instance-name>-egress) and LAN NSG (<instance-name>-lan) are
unchanged.
Check Point
Check Point firewalls share a single interface for egress and management traffic. Egress NSG (<instance-name>-egress):
LAN NSG (
<instance-name>-lan) is unchanged.
Fortinet
Fortinet firewalls share a single interface for egress and management traffic. Egress NSG (<instance-name>-egress):
LAN NSG (
<instance-name>-lan) is unchanged.
Behavior on Controller IP Change
When the Controller IP changes, Aviatrix updates the affected NSG rules on existing firewall instances:Limitations
- The Panorama placeholder rule (TCP 3978) starts with the Controller IP as the source. If you use Panorama, update the source to your Panorama server IP.
- Firewall instances launched before this feature was introduced keep their original NSG rules in addition to the new controller-scoped rules.