- Policies
- Monitor
- Audit
- IPS
- TLS
- Settings
Purpose
The Policies page creates and manages distributed firewall policies for securing traffic across the multicloud environments.Elements

- + Rule button: Starts the workflow to create a new firewall rule.
- Manage Rulesets: Opens the dialog to create, edit, or manage rulesets (groupings of rules). Create rulesets before adding rules to them (Controller 8.0 or later).
- Actions button: For the selected rule(s), provides options to Reset Hit Count, Monitor (stop enforcing without deleting the rule), and Enforce.
- Policy Table: Displays the rule names and their details.
- Edit button: Modifies an existing firewall rule in the table.
- Move button: Changes the priority order of the firewall rules.
- Delete button: Removes an existing firewall rule from the table.
Actions
Configure Rulesets
Configure Rulesets
View Ruleset
View Ruleset
- Go to Security > Distributed Cloud Firewall > Policies.
The Policies page appears with the ruleset list and the Policy Table. - To view the full list of rulesets and their order, click Manage Rulesets.
The Manage Rulesets dialog displays all rulesets and their priority order. - Click Close to return to the Policies tab.
- On the Policies tab, select a ruleset from the ruleset list (dropdown or selector).
The Policy Table shows the rules in that ruleset. - Optionally, use Search or Filter to find a rule within the ruleset.
Requires Controller version 8.0 or later.
Manage Rulesets
Manage Rulesets
- View all rulesets and their order
- Create rulesets
- Edit placement and names
- Change ruleset priority
- Reset traffic counts for selected rulesets
- Commit draft changes
- Go to Security > Distributed Cloud Firewall > Policies.
- Click Manage Rulesets.
The Manage Rulesets dialog appears. - Click the edit icon to edit the ruleset change the name and placement of the ruleset.
- Click the move icon to change the ruleset priority.
- Click the reset icon to reset the traffic counts for the selected rulesets.
- Click Save.
- Repeat steps 3–6 to create additional rulesets if needed.
- Click Commit to commit the saved changes.
- Click Close.
Create a DCF Ruleset
Create a DCF Ruleset
- Go to Security > Distributed Cloud Firewall > Policies.
- Click Manage Rulesets.
The Manage Rulesets dialog appears. - Click + Ruleset.
The Create Ruleset dialog appears. - Configure Name, Place Ruleset, and Existing Ruleset (if applicable).
Refer to the Parameter Details table. - Click Save.
- Repeat steps 3–5 to create additional rulesets if needed.
- Click Close.
- On the Policies tab, select a ruleset from the Ruleset dropdown to add rules to it.
Parameter Details
| CoPilot Parameter Name | Description |
|---|---|
| Name | Enter a name for the ruleset. |
| Place Ruleset | Select where to place the ruleset: above or below an existing ruleset, or at the top or bottom of the ruleset list. |
| Existing Ruleset | If you select Above or Below in Place Ruleset, select the existing ruleset from this list. |
Manage Firewall Rules
Manage Firewall Rules
Create Firewall Rule
Create Firewall Rule
- Go to Security > Distributed Cloud Firewall > Policies.
- Click + Rule.
- Configure the rule parameters. Refer to the Parameter Details table.
- Save the rule.
Parameter Details
| CoPilot Parameter Name | Description |
|---|---|
| Name | Distributed Cloud Firewall rule name. |
| Source Groups | The groups (SmartGroup, ExternalGroup, Threat Feed, Country) that originate traffic. You must create the SmartGroups and ExternalGroups before creating a DCF rule. Note: You must include at least one SmartGroup. You cannot have an ExternalGroup as both a source and a destination. |
| Destination Groups | The groups (SmartGroup, ExternalGroup, Threat Feed, Country) that terminate traffic. You must create the SmartGroups and ExternalGroups before creating a DCF rule. Note: You must include at least one SmartGroup. You cannot have an ExternalGroup as both a source and a destination. If you are using Distributed Cloud Firewall rules for egress purposes, you must:
The Destination Group must be Public Internet if all of the following are true:
|
| WebGroups | Select the WebGroups that filter egress traffic. You must create these groups before creating a DCF rule. |
| Protocol | Select TCP, UDP, ICMP, or Any. If you select TCP or UDP you can enter a port number or port range. Note: If a WebGroup is included in the rule, a warning displays if any non-standard ports are selected for TCP or UDP. Non-standard ports are those that are not commonly used for the selected protocol, such as port 80 for HTTP or port 443 for HTTPS. The ICMP protocol is unavailable if a WebGroup is selected, because WebGroups are only supported for TLS traffic. If UDP or ICMP is selected, Ensure TLS and TLS Decryption toggles are unavailable. |
| Port | Enter a port numbers or port range for the protocol. |
| Local Egress | Available starting in Controller 10.1. If this slider is On, for a Permit rule that matches egress traffic, traffic exits directly through the Spoke Gateway’s eth0 interface instead of routing to a centralized firewall.If this slider is Off (default), matching traffic routes to a centralized egress gateway, such as a Transit FireNet or Transit Egress gateway, for inspection before it exits. Note: Before you turn on Local Egress, make sure of the following:
|
| Rule Behavior | |
| State |
|
| Action | Select Permit or Deny. This determines the action applied to matching traffic. |
| Log |
Note: Aviatrix recommends not logging Permit rules. |
| SG Orchestration | On: The rule is available for Security Group Orchestration. The SG Orchestration toggle is Off for new rules when any of the following are true:
|
| Ensure TLS | Turn On if you want traffic that matches the ports and Source and Destination Groups but that is not TLS to be denied. Traffic is denied (dropped) even if HTTP traffic matches domains or URLs in WebGroups. |
| TLS Decryption | Turn On to enable TLS decryption. Important: TLS Decryption must be enabled if a URL-based WebGroup is selected. TLS decryption intercepts encrypted HTTPS traffic, decrypts it for inspection, then re-encrypts it toward the destination. |
| Intrusion Analysis | When Intrusion Detection is enabled, traffic is inspected for threats and results appear on Detected Intrusions. When Intrusion Detection and TLS Decryption are both enabled, the TLS stream is temporarily decrypted and inspected for intrusions. Note: Download the Aviatrix CA certificate (Controller 7.0) or upload your own certificate (Controller 7.1 or later) before creating a policy that uses IDS or TLS Decryption. |
| TLS Profile | Select the TLS profile to use for the rule. |
| Rule Priority | |
| Place Rule | Select Above, Below, Top, Bottom, or Priority. |
| Existing Rule | If you select Above or Below for Place Rule, select the existing rule whose position is affected by the new rule. |
| Priority Number | If you selected Priority for Place Rule, enter a priority number for the new rule. If another rule already has that priority, it moves down in the list. Zero (0) is the highest priority number. You can change rule priority after creation using the arrow icon next to the rule in the Rule table. |
Edit Firewall Rule
Edit Firewall Rule
- Go to Security > Distributed Cloud Firewall > Policies.
- Locate the rule in the Policy table and click the Edit button.
- Update the desired parameters.
- Save your changes.
Move Firewall Rule
Move Firewall Rule
- Go to Security > Distributed Cloud Firewall > Policies.
- Locate the rule in the Policy Table and click the Move button.
- Move the rule to the desired position in the priority order.
- Save the new order.
Delete Firewall Rule
Delete Firewall Rule
- Go to Security > Distributed Cloud Firewall > Policies.
- Locate the rule in the Policy Table and click the Delete button.
- Confirm the deletion.
Manage Policy State
Manage Policy State
- Go to Security > Distributed Cloud Firewall > Policies.
- Select the checkbox for the rule(s) in the Policy Table.
- Click the Actions button.
- Select Reset Hit Count, Monitor, or Enforce as needed.
- Policy Logs
- Intrusion Logs
Purpose
The Policy Logs page displays traffic logs generated by the Distributed Cloud Firewall policies. It helps monitor allowed and denied traffic, and supports troubleshooting and audit of policy enforcement across cloud networks.Elements

- Auto Refresh toggle: Enables or disables automatic refreshing of the log data.
- Policy Logs table: Displays policy rule logs and their details.
Actions
View Policy Logs
View Policy Logs
- Go to Security > Distributed Cloud Firewall > Monitor.
Select the Policy Logs tab. - The Policy Logs page appears with the Policy Logs table.
- Review traffic logs for allowed and denied traffic.
- Optionally, use the Auto Refresh toggle to enable or disable automatic refreshing of log data.
Parameter Details
| CoPilot Parameter Name | Description |
|---|---|
| Timestamp | Shows the date and time when the traffic log is recorded. |
| Rule | Shows the firewall policy rule that matches the traffic. |
| Gateway | Shows the gateway that processes the traffic. |
| Source IP | Shows the source IP address of the traffic. |
| Destination IP | Shows the destination IP address of the traffic. |
| Source MAC address | Shows the source MAC address of the traffic. |
| Destination MAC address | Shows the destination MAC address of the traffic. |
| SNI | Shows the server name indication extracted from TLS traffic. |
| Decrypted by | Shows the gateway that performs traffic decryption. |
| URL | Shows the destination URL accessed by the traffic. |
| Protocol | Shows the traffic protocol such as TCP, UDP, or ICMP. |
| Source port | Shows the source port number used by the traffic. |
| Destination port | Shows the destination port number used by the traffic. |
| Reason | Shows the reason for the policy decision. |
| Action | Shows whether the traffic is allowed or denied. |
| Enforced | Shows whether the policy enforcement is applied. |
| Local Egress | Available starting in Controller 10.1. Shows whether the matching session used Local Egress (traffic exited directly through the Spoke Gateway) or was routed to a centralized egress gateway. |
Purpose
The Intrusion Logs page displays security events detected by the Distributed Cloud Firewall intrusion detection engine. It helps identify suspicious traffic, analyze threats, and support security investigation across cloud environments.Elements

- Intrusion Logs table: Displays intrusion detection logs and their details.
Actions
View Intrusion Logs
View Intrusion Logs
- Go to Security > Distributed Cloud Firewall > Monitor.
Select the Intrusion Logs tab. - The Intrusion Logs page appears with the Intrusion Logs table.
- Review security events detected by the intrusion detection engine.
Parameter Details
| CoPilot Parameter Name | Description |
|---|---|
| Timestamp | Shows the date and time when the intrusion event is recorded. |
| Severity | Shows the severity level of the detected intrusion. |
| Source IP | Shows the source IP address of the traffic. |
| Destination IP | Shows the destination IP address of the traffic. |
| Protocol | Shows the network protocol used by the traffic. |
| Source port | Shows the source port number used by the traffic. |
| Destination port | Shows the destination port number used by the traffic. |
| Application protocol | Shows the application-level protocol detected in the traffic. |
| Gateway | Shows the gateway where the intrusion is detected. |
| Category | Shows the intrusion category or attack type. |
| Attack target | Shows the target resource of the detected attack. |
| Deployment | Shows the deployment or environment where the event occurs. |
Purpose
The Audit page displays audit logs for Distributed Cloud Firewall operations. It helps track user actions, review configuration changes, and support security audit and troubleshooting activities.Elements

- Time Period filter: Filters audit logs based on a selected time range.
Actions
View Audit Logs
View Audit Logs
- Go to Security > Distributed Cloud Firewall > Audit.
- The Audit page appears with audit logs for DCF operations.
- Optionally, use the Time Period filter to filter logs by a selected time range.
- Review user actions, configuration changes, and audit findings.
Parameter Details
| CoPilot Parameter Name | Description |
|---|---|
| Check Name | Shows the name of the audit check performed. |
| Status | Shows whether the audit check passed or failed. |
| Severity | Shows the severity level of the audit finding. |
| Resource | Shows the resource associated with the audit finding. |
| Details | Provides additional information about the audit finding. |
- Profiles
- Rules Feeds
Purpose
The Profiles page lists intrusion prevention profiles that you can attach to DCF rules for the prevention of network intrusions.Elements

- + Custom Profile: Opens the flow to define a new custom IPS profile.
- Profiles table: Lists added custom IPS profiles.
- Search bar: Narrow the profiles table by name or attributes.
- Edit: Edits the a custom IPS profile.
- Delete: Deletes the a custom IPS profile.
- Actions: Opens the context menu to clone a profile and set an IPS profile active.
Actions
View IPS Profiles
View IPS Profiles
- Go to Security > Distributed Cloud Firewall > IPS > Profiles.
- The IPS Profiles page appears with the IPS Profiles table.
- Refer to the Parameter Details table for the details of the IPS profiles parameters.
- Optionally use Search or the table toolbar filters to narrow rows.
Parameter Details
| CoPilot Parameter Name | Description |
|---|---|
| Name | The name of the IPS profile. |
| Drop Level | The minimum Suricata signature severity level at which matching traffic is dropped.
|
| Log Level | The severity level at which alerts are generated. |
| SID Exceptions | The total number of Signature ID (SID) overrides configured on the profile. Includes both Ignored SIDs (fully suppressed — no alert or drop) and Alert Only SIDs (alert generated, traffic not dropped) |
View an IPS Profile
View an IPS Profile
- Go to Security > Distributed Cloud Firewall > IPS > Profiles.
- Locate the IPS Profile in the table and click the profile name.
- The IPS Profile details page appears with the IPS Profile details.
- Refer to the Parameter Details table for the details of the IPS Profile parameters.
Parameter Details
| CoPilot Parameter Name | Description |
|---|---|
| Name | The name of the IPS profile. |
| Drop Level | |
| Log Level | |
| Rule Feeds | |
| SID | The SID exceptions in the IPS profile. |
| Action | The action to take when the SID is matched. |
Create a Custom IPS profile
Create a Custom IPS profile
- Go to Security > Distributed Cloud Firewall > IPS > Profiles.
- Click + Custom Profile.
- Configure the profile parameters. Refer to the Parameter Details table.
- Click Save.
Parameter Details
| CoPilot Parameter Name | Description |
|---|---|
| Name | The name of the IPS profile. |
| Rule Feed | |
| Drop Level |
|
| Alert Level |
Edit an IPS profile
Edit an IPS profile
- Go to Security > Distributed Cloud Firewall > IPS > Profiles.
- Locate the IPS Profile in the table and click the edit icon.
The Edit IPS Profile form appears. - Update the profile parameters. Refer to the Parameter Details table.
- Click Save.
Parameter Details
| CoPilot Parameter Name | Description |
|---|---|
| Name | The name of the IPS profile. |
| Rule Feed | |
| Drop Level |
|
| Alert Level |
Delete an IPS profile
Delete an IPS profile
- Go to Security > Distributed Cloud Firewall > IPS > Profiles.
- Locate the IPS Profile in the table and click the delete icon.
The Delete IPS Profile confirmation dialog appears. - Click Delete.
Clone an IPS Profile
Clone an IPS Profile
- Go to Security > Distributed Cloud Firewall > IPS > Profiles.
- Locate the IPS Profile in the table and click Actions (⋮) > Clone profile.
The Clone Profile form appears. - Update the profile parameters. Refer to the Parameter Details table.
- Click Clone.
Parameter Details
| CoPilot Parameter Name | Description |
|---|---|
| Name | The name of the IPS profile. |
| Rule Feed | |
| Drop Level |
|
| Alert Level |
Set an IPS Profile Active
Set an IPS Profile Active
- Go to Security > Distributed Cloud Firewall > IPS > Profiles.
- Locate the IPS Profile in the table and click Actions (⋮) > Set As Active.
- Read and understand the message, and tick to confirm the setting.
- Click Apply.
Purpose
The Rules Feeds page lists intrusion prevention rules used when IPS inspection runs for Distributed Cloud Firewall.Elements

- + Custom Rule Federal: Opens the form to define a new custom IPS rule.
- Rules table: Lists added custom IPS rules.
- Search bar: Narrow the rules table by name or attributes.
- Edit button: Edits the a custom IPS rule.
- Delete button: Deletes the a custom IPS rule.
- Actions (⋮) button: Opens the context menu to download a rule feed.
Actions
View Custom Rules
View Custom Rules
- Go to Security > Distributed Cloud Firewall > IPS > Rules Feeds.
- The Custom Rules page appears with the Custom Rules table.
- Refer to the Parameter Details table for the details of the Custom Rules parameters.
- Optionally use Search or the table toolbar filters to narrow rows.
Parameter Details
| CoPilot Parameter Name | Description |
|---|---|
| Name | The name of the customIPS rule. |
| Rules | The number of rules in the custom IPS rule. |
| Last Updated | The date and time the custom IPS rule was last updated. |
View a Custom Rule
View a Custom Rule
- Go to Security > Distributed Cloud Firewall > IPS > Rules Feeds.
- Locate the custom Rule in the table and click the name of the rule.
The Custom Rule details page appears with the Custom Rule details.
Refer to the Parameter Details table for the details of the Custom Rule parameters.
Parameter Details
| CoPilot Parameter Name | Description |
|---|---|
| SID | The SID of the custom Rule. |
| Content | The content of the custom Rule. |
| Severity | The severity of the custom Rule. |
Create a Custom Rule Feed
Create a Custom Rule Feed
- Go to Security > Distributed Cloud Firewall > IPS > Rules Feeds.
- Click + Custom Rule Feed.
- Enter the name of the custom IPS rule.
- Upload the custom IPS rule feed file.
- Click Upload.
Edit a Custom Rule Feed
Edit a Custom Rule Feed
- Go to Security > Distributed Cloud Firewall > IPS > Rules Feeds.
- Locate the custom Rule Feed in the table and click the edit icon in the row.
The Edit Custom Rule Feed form appears. - Update the name of the custom Rule Feed and upload new rule feed file.
- Click Upload.
Edit a Custom Rule Syntax
Edit a Custom Rule Syntax
- Go to Security > Distributed Cloud Firewall > IPS > Rules Feeds.
- Locate the custom Rule Feed in the table and click the name of the rule.
The Custom Rule Syntax details page appears with a table of the SID and the rule syntax. - Click the edit icon in the row and edit the rule syntax.
- Turn On the Suricata Rule Syntax toggle to edit the rule syntax in the Suricata format.
Refer to the Parameter Details table for the details of the Suricata Rule Syntax parameters. - Click Save. A notification appears confirming the update of the custom Rule Syntax.
Parameter Details
| CoPilot Parameter Name | Description |
|---|---|
| Severity |
|
| Rule | |
| Action |
|
| Protocol |
|
| Direction |
|
| Source | |
| Source Port | |
| Destination | |
| Destination Port | |
| Options |
Delete a Custom Rule Feed
Delete a Custom Rule Feed
- Go to Security > Distributed Cloud Firewall > IPS > Rules Feeds.
- Locate the custom Rule Feed in the table and click the delete icon in the row.
The Delete Custom Rule Feed confirmation dialog appears. - Click Delete. A notification appears confirming the deletion of the custom Rule Feed.
Download a Custom Rule Feed
Download a Custom Rule Feed
- Go to Security > Distributed Cloud Firewall > IPS > Rules Feeds.
- Locate the custom Rule Feed in the table and click the Actions icon (⋮) in the row.
The Actions menu appears. - Click Download Rule Feed. A notification appears on your browser confirming the download of the custom Rule Feed.
- Profiles
- Decryption CA Certificates
- Trust Bundles
Purpose
The Profiles page is a central management hub for creating, configuring, and managing TLS Profile objects that control how the Distributed Cloud Firewall inspects, validates, and decrypts TLS traffic.Elements

- + Custom Profile: Opens the flow to create a new custom TLS profile.
- Search: Filters rows in the profiles table.
- Profiles table: Shows the list of TLS profiles and their trust and enforcement settings.
- Actions: Edit, Delete, and More (⋮) buttons to edit, delete, and clone a profile.
Actions
View TLS Profiles
View TLS Profiles
- Go to Security > Distributed Cloud Firewall > TLS > Profiles.
The Profiles page appears with the Profiles table. - Refer to the Parameter Details table for the details of the TLS profiles parameters.
- Optionally use Search or the table toolbar filters to narrow rows. The table displays TLS profiles with their name, trust bundle, SNI verification, and enforcement settings.
Parameter Details
| CoPilot Parameter Name | Description |
|---|---|
| Name | The name of the TLS profile. |
| Trust Bundle | Collection of CA certificates used to validate the origin server’s certificate when this TLS profile is applied to a rule. |
| SNI Verification |
|
| Enforcement |
|
Create a TLS Profile
Create a TLS Profile
- Go to Security > Distributed Cloud Firewall > TLS > Profiles.
- Click + Custom Profile.
- Configure the profile parameters. Refer to the Parameter Details table.
- Click Save.
Parameter Details
| CoPilot Parameter Name | Description |
|---|---|
| Name | Enter a name for the TLS profile. |
| Trust Bundle | Collection of CA certificates used to validate the origin server’s certificate when this TLS profile is applied to a rule. |
| SNI Verification |
|
| Enforcement |
|
Edit a TLS Profile
Edit a TLS Profile
- Go to Security > Distributed Cloud Firewall > TLS > Profiles.
The Profiles page appears with the Profiles table. - Locate the profile and use Edit to update the profile parameters. Refer to the Parameter Details table.
- Use More actions (⋮) and click Clone to create a copy of the profile.
- Click Save.
Parameter Details
| CoPilot Parameter Name | Description |
|---|---|
| Name | The name of the TLS profile. |
| Trust Bundle | Collection of CA certificates used to validate the origin server’s certificate when this TLS profile is applied to a rule. |
| SNI Verification |
|
| Enforcement |
|
Delete a TLS Profile
Delete a TLS Profile
- Go to Security > Distributed Cloud Firewall > TLS > Profiles.
The Profiles page appears with the Profiles table. - Locate the profile and click Delete.
- Read the warning message and tick to confirm the deletion.
- Click Delete. A notification appears confirming the deletion.
Purpose
The Decryption CA Certificates page shows the CoPilot-managed Decryption CA used for TLS decryption in DCF flows, its validity, association to a trust bundle, and actions to renew or download the certificate.Elements

- Decryption CA Certificate Certificate card showing the certificate details such as name, expiry date, and trust bundle association.
- Renew Certificate button: Button to renew the decryption CA certificate.
- Download Certificate button: Button to download the decryption CA certificate.
- More Options dropdown: The dropdown menu contains the following options:
- Upload New Certificate: Button to upload a new certificate.
- Upload New Trust Bundle: Button to upload a new trust bundle.
- Remove Certificate: Button to remove the certificate.
- Remove Trust Bundle: Button to remove the trust bundle.
Actions
Renew a Decryption CA Certificate
Renew a Decryption CA Certificate
- Go to Security > Distributed Cloud Firewall > TLS > Decryption CA Certificates.
- Locate the Decryption CA Certificate card to renew.
- Click Renew Certificate.
Download a Decryption CA Certificate
Download a Decryption CA Certificate
- Go to Security > Distributed Cloud Firewall > TLS > Decryption CA Certificates.
- Locate the Decryption CA Certificate card to download.
- Click Download Certificate. A notification on your browser appears confirming the download.
Upload a New Certificate
Upload a New Certificate
- Go to Security > Distributed Cloud Firewall > TLS > Decryption CA Certificates.
- Locate the Decryption CA Certificate card to upload.
- Click the dropdown next to the Download Certificate button and click Upload New Certificate.
The Upload New Certificate dialog appears. - Upload the Certificate and the Certificate Key.
- Click Upload. A notification appears confirming the upload.
Upload a New Trust Bundle
Upload a New Trust Bundle
- Go to Security > Distributed Cloud Firewall > TLS > Decryption CA Certificates.
- Locate the Decryption CA Certificate card to upload.
- Click the dropdown next to the Download Certificate button and click Upload Trust Bundle.
The Upload Trust Bundle dialog appears. - Upload the trust bundle file.
- Click Upload. A notification appears confirming the upload.
Remove a Certificate
Remove a Certificate
- Go to Security > Distributed Cloud Firewall > TLS > Decryption CA Certificates.
- Locate the Decryption CA Certificate card to remove.
- Click the dropdown next to the Download Certificate button and click Remove Certificate.
The Remove Certificate dialog appears. - Click Remove. A notification appears confirming the removal.
Remove a Trust Bundle
Remove a Trust Bundle
- Go to Security > Distributed Cloud Firewall > TLS > Decryption CA Certificates.
- Locate the Decryption CA Certificate card to remove.
- Click the dropdown next to the Download Certificate button and click Remove Trust Bundle.
The Remove Trust Bundle dialog appears. - Click Remove. A notification appears confirming the removal.
Purpose
The Trust Bundles view lists trust bundles available for TLS operations (including those referenced by TLS profiles and the decryption CA configuration).Elements

- + Trust Bundle: Button to start the workflow for adding a new trust bundle.
- Trust Bundles table: Displays the list of added trust bundles and their details.
- Search: Filters trust bundle rows in the table.
Actions
View Trust Bundles
View Trust Bundles
- Go to Security > Distributed Cloud Firewall > TLS > Trust Bundles.
- The Trust Bundles page appears with the Trust Bundles table.
- Refer to the Parameter Details table for the details of the trust bundles parameters.
- Optionally, use Search or the table toolbar filters to narrow rows. The table displays trust bundles with their name.
Add a Trust Bundle
Add a Trust Bundle
- Go to Security > Distributed Cloud Firewall > TLS > Trust Bundles.
- Click + Trust Bundle.
- Enter the name of the trust bundle.
- Upload the trust bundle file.
Note: Ensure the trust bundle file is in .pem format.
- Click Save. A notification appears confirming the addition.
Edit a Trust Bundle
Edit a Trust Bundle
- Go to Security > Distributed Cloud Firewall > TLS > Trust Bundles.
- Locate the trust bundle and click the edit icon in the row.
The Edit Trust Bundle dialog appears. - Update the name of the trust bundle and upload new trust bundle file.
- Click Save.
A notification appears confirming the update.
Note: Ensure the trust bundle file is in .pem format.
Delete a Trust Bundle
Delete a Trust Bundle
- Go to Security > Distributed Cloud Firewall > TLS > Trust Bundles.
The Trust Bundles page appears with the Trust Bundles table. - Locate the trust bundle and click the delete icon in the row.
- Read the warning message and tick to confirm the deletion.
- Click Delete. A notification appears confirming the deletion.
Download a Trust Bundle
Download a Trust Bundle
- Go to Security > Distributed Cloud Firewall > TLS > Trust Bundles.
The Trust Bundles page appears with the Trust Bundles table. - Locate the trust bundle and click the Actions icon (⋮) in the row.
- Click Download Trust Bundle. A notification on your browser appears confirming the download.
Purpose
The Settings page controls where Distributed Cloud Firewall (DCF) policies are enforced across clouds, gateways, external connections, Kubernetes, and other targets. It also shows intrusion signature update status, log enrichment options, and the master DCF enable/disable control.Elements

- Enforcement on Clouds: Controls the application of DCF policy on onboarded clouds. Shows Enforced On (the cloud providers with enforcement enabled) and a Manage button.
Note: Enforcement on Clouds is labeled Preview in the CoPilot UI.
- Enforcement on Gateways: Table with Type and Gateways columns listing Spoke Gateways, Transit Gateways, Transit Egress Gateways, and Public Subnet Filtering Gateways with the count of gateways enforcing DCF in each category. Gateway type names are links that open a detail dialog.
- Security Group (SG) Orchestration: Adds DCF control for Intra-VPC Traffic and Inbound Internet Access on selected VPC/VNets. Shows Available On or Enabled On (VPC/VNet count), orchestration status when enabled, View in Topology (when at least one VPC/VNet is enabled), and Manage.
Note: Security Group (SG) Orchestration is labeled Preview in the CoPilot UI.
- Enforcement on PSF Gateways: Controls DCF policy on Public Subnet Filtering (PSF) gateways. Shows Status (Enabled or Disabled) and Enable or Disable.
- Enforcement on External Connections: Controls DCF policy on External Connections (S2C). Shows Status (Enabled or Disabled) and Enable or Disable.
- Enforcement on Transit Egress: Controls DCF policy on Transit Egress. Shows Status (Enabled or Disabled) and Enable or Disable. Policies are not applied on gateways where Legacy FQDN is enabled (Egress Instances are attached).
Note: Enforcement on Transit Egress is labeled Preview in the CoPilot UI.
- Enforcement on Kubernetes via Custom Resource Definitions (CRDs): Controls DCF policy on Kubernetes. Shows Status (Enabled or Disabled), View Prerequisites, and Enable or Disable.
Note: Enforcement on Kubernetes via Custom Resource Definitions (CRDs) is labeled Preview in the CoPilot UI.
- Intrusion Signatures: Shows Last Updated — the date and time intrusion detection signatures were last updated.
- Log Enrichment: Toggle to add additional meta-information to security logs, including workload name and properties.
Note: Log Enrichment is labeled Preview in the CoPilot UI.
- Distributed Cloud Firewall: Master control for DCF enforcement across the Aviatrix managed environment. Shows Enable, Disable, or Clean Up Policies (when DCF is disabled and policies remain).
Actions
Manage Enforcement on Clouds
Manage Enforcement on Clouds
- Go to Security > Distributed Cloud Firewall > Settings.
- On the Enforcement on Clouds card, click Manage.
The Manage Enforcement on Clouds dialog appears with a table of cloud providers. - Use the Enforcement toggle for each provider to turn enforcement on or off.
- Click Save.
You must have enforcement turned on for at least one cloud to save.
Parameter Details
| CoPilot Parameter Name | Description |
|---|---|
| Name | Cloud provider name (for example, AWS, Azure ARM, GCP, AWS GovCloud, or Azure Government). |
| Cloud Accounts | Number of onboarded cloud accounts for the provider. |
| Enforcement | Toggle to enable or disable DCF enforcement on the provider. |
View Enforcement on Gateways
View Enforcement on Gateways
- Go to Security > Distributed Cloud Firewall > Settings.
- On the Enforcement on Gateways card, review the Type and Gateways columns.
- Click a gateway type link (Spoke Gateways, Transit Gateways, Transit Egress Gateways, or Public Subnet Filtering Gateways).
A dialog lists gateways of that type with DCF enforcement details.
Parameter Details
| CoPilot Parameter Name | Description |
|---|---|
| Type | Gateway category: Spoke Gateways, Transit Gateways, Transit Egress Gateways, or Public Subnet Filtering Gateways. |
| Gateways | Count of gateways in the category that enforce DCF policies. |
Manage Security Group Orchestration
Manage Security Group Orchestration
- Go to Security > Distributed Cloud Firewall > Settings.
- On the Security Group (SG) Orchestration card, click Manage.
The Manage Security Group Orchestration dialog appears. - Select the VPC/VNets to enable or disable Security Group Orchestration.
- Save your changes.
Enable or Disable Enforcement on PSF Gateways
Enable or Disable Enforcement on PSF Gateways
- Go to Security > Distributed Cloud Firewall > Settings.
- On the Enforcement on PSF Gateways card, click Enable.
Enforcement turns on immediately.
- Go to Security > Distributed Cloud Firewall > Settings.
- On the Enforcement on PSF Gateways card, click Disable.
A confirmation dialog appears asking “Are you sure you want to disable Enforcement on PSF Gateways?” - Select the acknowledgement checkbox (“I understand that the security posture and network traffic through the PSF Gateways could change.”).
- Click Disable to confirm.
Enable or Disable Enforcement on External Connections
Enable or Disable Enforcement on External Connections
- Go to Security > Distributed Cloud Firewall > Settings.
- On the Enforcement on External Connections card, click Enable.
Enforcement turns on immediately.
- Go to Security > Distributed Cloud Firewall > Settings.
- On the Enforcement on External Connections card, click Disable.
A confirmation dialog appears asking “Are you sure you want to disable Enforcement on External Connections?” - Select the acknowledgement checkbox (“I understand that the security posture and network traffic through the External Connections could change.”).
- Click Disable to confirm.
Enable or Disable Enforcement on Transit Egress
Enable or Disable Enforcement on Transit Egress
- Go to Security > Distributed Cloud Firewall > Settings.
- On the Enforcement on Transit Egress card, click Enable.
Enforcement turns on immediately.
- Go to Security > Distributed Cloud Firewall > Settings.
- On the Enforcement on Transit Egress card, click Disable.
A confirmation dialog appears asking “Are you sure you want to disable Enforcement on Transit Egress?” - Select the acknowledgement checkbox (“I understand that the security posture and network traffic through the Transit Egress could change.”).
- Click Disable to confirm.
Enable or Disable Enforcement on Kubernetes
Enable or Disable Enforcement on Kubernetes
- Go to Security > Distributed Cloud Firewall > Settings.
- On the Enforcement on Kubernetes via Custom Resource Definitions (CRDs) card, optionally click View Prerequisites to review requirements.
- Click Enable or Disable.
Enable is unavailable until Kubernetes resource discovery is enabled in Groups > Settings.
Parameter Details
| CoPilot Parameter Name | Description |
|---|---|
| Status | Whether DCF policy enforcement on Kubernetes is enabled or disabled. |
| View Prerequisites | Opens a dialog listing prerequisites for Kubernetes DCF enforcement. |
View Intrusion Signatures Last Updated
View Intrusion Signatures Last Updated
- Go to Security > Distributed Cloud Firewall > Settings.
- On the Intrusion Signatures card, review Last Updated.
Parameter Details
| CoPilot Parameter Name | Description |
|---|---|
| Last Updated | Date and time the intrusion detection signatures were last updated. |
Enable or Disable Log Enrichment
Enable or Disable Log Enrichment
- Go to Security > Distributed Cloud Firewall > Settings.
- On the Log Enrichment card, turn the toggle On or Off.
- Click Save.
- If disabling, read the confirmation message, acknowledge the implications, and click Disable.
Parameter Details
| CoPilot Parameter Name | Description |
|---|---|
| Log Enrichment | Toggle to add additional meta-information to security logs, including workload name and properties. |
Enable or Disable Distributed Cloud Firewall
Enable or Disable Distributed Cloud Firewall
- Go to Security > Distributed Cloud Firewall > Settings.
- On the Distributed Cloud Firewall card at the bottom of the page, click Enable or Disable.
- Read the confirmation message and confirm the change.