Skip to main content
This section provides the purpose, elements, and actions performed on the FireNet pages.

Purpose

The FireNet page provides centralized management for firewall insertion into Aviatrix Transit architecture, enabling advanced security inspection across multicloud environments.
Controller version 9.0 extends IPv6 FireNet vendor support to Fortinet and Check Point, in addition to Palo Alto Networks (supported from Controller version 8.2).

Elements

FireNet: FireNet
  • + FireNet split button: Opens the Add FireNet to Transit Gateway dialog. Its dropdown offers Add Egress Transit FireNet and Add AWS TGW FireNet as alternate FireNet types to create.
  • Select columns button: Button to customize visible columns. VPC/VNet and Cloud Load Balancer are hidden by default.
  • Show filters / Export buttons: Filter and export the table.
  • FireNet table: Lists Transit Gateways with FireNet configured, along with their firewall attachment and inspection status.

Actions

To view FireNet instances and their status:
  1. Go to Security > FireNet > FireNet.
  2. The FireNet page appears with the table of Transit Gateways configured for FireNet.
  3. Click a Transit Gateway name to open its FireNet detail page.

Parameter Details

Before creating a FireNet, ensure the target Transit Gateway exists and (for AWS TGW FireNet) the AWS TGW is attached.To create a FireNet:
  1. Go to Security > FireNet > FireNet.
  2. Click + FireNet to create a Transit FireNet, or use the dropdown to choose Add Egress Transit FireNet or Add AWS TGW FireNet.
  3. In the dialog, select the Transit Gateway, configure the firewall instance size, and complete the remaining fields for the selected FireNet type.
  4. Click Add.
The new FireNet appears in the table once provisioning completes.
To attach or detach firewall instances from a FireNet:
  1. Go to Security > FireNet > FireNet.
  2. In the row’s action menu, click Manage Firewall Attachment.
    The Manage Firewall Attachment dialog appears.
  3. In Firewall, add or remove firewall instances to attach or detach them.
  4. Click Save.
To view or manage the details of a FireNet:
  1. Go to Security > FireNet > FireNet.
  2. Click the Transit Gateway name for the FireNet.
The FireNet detail page opens with the following tabs:
Before configuring vendor integration through Firewall Manager, ensure you have:
  • A Transit FireNet gateway with firewall instances attached
  • (For Palo Alto Networks Panorama) Panorama management IP address and administrator credentials
  • (For Palo Alto Networks Panorama) Panorama template and template stack names to assign to each firewall
To configure vendor integration through Firewall Manager:
  1. Go to Security > FireNet > FireNet.
  2. Click the Transit Gateway name for the FireNet, then open its Vendor Integration tab.
  3. Click Through Firewall Manager as the integration path.
  4. In Firewall Manager Vendor, click the Firewall Manager Vendor dropdown. Select Palo Alto Networks Panorama to configure Custom Firewall Mapping.
  5. In Management IP Address, enter the management IP address of the Panorama instance.
  6. In Username, enter the Panorama administrator username.
  7. In Password, enter the corresponding password.
  8. In FireNet Instance Template Name, select or enter the template to assign to this firewall.
    Enable Custom Firewall Mapping to configure more than one firewall template.
  9. Click Save.
A notification appears confirming the vendor integration configuration.
To remove a FireNet:
  1. Go to Security > FireNet > FireNet.
  2. In the row’s action menu, click Remove.
  3. Confirm the removal.
Removing a FireNet is available only for AWS. For other clouds, Remove is disabled with a tooltip explaining that the FireNet must be removed through Terraform or the Controller.
To run FireNet diagnostics for troubleshooting:
  1. Go to Security > FireNet > FireNet.
  2. In the row’s action menu, click FireNet Diagnostics.
  3. Run Ping, Traceroute, or view logs for the selected FireNet.
Diagnostics help troubleshoot connectivity and operational issues with FireNet instances.