> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aviatrix.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Managing Egress Security for VPC/VNets

> Controller 8.0 is required for all features and functionality on this tab except for applying local egress to VPC/VNets.

<Note>
  Controller 8.0 is required for all features and functionality on this tab
  except for applying local egress to VPC/VNets.
</Note>

<a id="start-help-egress-tab" />

The Egress VPC/VNets tab displays all VPC/VNets discovered by your cloud
accounts and their <a href={"/docs/enterprise/" + "10.1" +
"/reference/egress-filtering/egress-security-score#egress-score-calculation"}>protection
status</a>.

VPC/VNets with No Egress status require the deployment of a Spoke gateway for
Local Egress.

<img src="https://mintcdn.com/aviatrix-14b37c43/mOZ0lmP7pRPIryx3/images/guides/security/egress/egress-vpc-vnets-tab.png?fit=max&auto=format&n=mOZ0lmP7pRPIryx3&q=85&s=75211d6ec21b1e1655fcac489ac48cd9" alt="Egress VPC/VNets tab" width="2972" height="1180" data-path="images/guides/security/egress/egress-vpc-vnets-tab.png" />

The Egress VPC/VNets tab displays:

* Spoke gateways that have Local Egress enabled (Spoke gateways that send
  traffic directly to the Internet).
* Spoke gateways that have Transit Egress enabled (Spoke gateways that forward
  traffic to a Transit gateway, which then sends the traffic to the Internet).

<Note>
  This Transit gateway must have Transit Egress Capability (selectable when you
  [create a Transit
  gateway](https://legacy.docs.aviatrix.com/documentation/latest/network/transit-gateway-about.html?expand=true)).
</Note>

* Spoke gateways where Egress is not configured by Aviatrix (Native Cloud
  Egress). These are not editable.
* GCP Spoke gateways that have Global VPC and Transit Egress enabled. These are
  not editable.
* Any Transit gateways attached to the Spoke gateways.

## Actions on the Egress VPC/VNets Tab

You can do the following on this tab if you have upgraded to Controller 8.0 and
have the DCF feature enabled:

* [Deploy a Spoke Gateway within a VPC/VNet](https://legacy.docs.aviatrix.com/documentation/latest/security/egress-deploy-spoke-gateway.html),
  so that Local Egress can be applied
* <a href={"/docs/enterprise/" + "10.1" + "/guides/security/egress/egress-enabling-local"}>Apply Local Egress to VPC/VNets</a>
* <a href={"/docs/enterprise/" + "10.1" + "/guides/security/egress/egress-enabling-local#remove-local-egress"}>Remove Local Egress from VPC/VNets</a>
* <a href={"/docs/enterprise/" + "10.1" + "/guides/security/egress/egress-monitor-vpc-vnets"}>Monitor VPC/VNets</a>
  , to determine if any of them require protection
* <a href={"/docs/enterprise/" + "10.1" + "/guides/security/egress/egress-protect-vpc-vnets"}>Protect VPC/VNets</a>
  by only allowing trusted traffic flows
* <a href={"/docs/enterprise/" + "10.1" + "/guides/security/egress/egress-unprotect-monitor"}>Unprotect but still monitor VPC/VNets</a>
* <a href={"/docs/enterprise/" + "10.1" + "/reference/egress-filtering/egress-security-score#ignore-egress-score"}>Include VPC/VNets in the Egress Security Score</a>
* <a href={"/docs/enterprise/" + "10.1" + "/reference/egress-filtering/egress-security-score#ignore-egress-score"}>Exclude VPC/VNets from the Egress Security Score</a>

You can do the following on this tab if you have not yet upgraded to Controller
8.0:

* <a href={"/docs/enterprise/" + "10.1" + "/guides/security/egress/egress-enabling-local"}>Apply Local Egress to VPC/VNets</a>
* <a href={"/docs/enterprise/" + "10.1" + "/guides/security/egress/egress-enabling-local#remove-local-egress"}>Remove Local Egress from VPC/VNets</a>

## Views on the Egress VPC/VNets Tab

The following views are available on the Egress VPC/VNets tab:

* Default View: Shows a comprehensive view of all VPC/VNets where Local Egress
  is enabled, including their protection status.
* Local Egress: Displays VPC/VNets with Local Egress enabled, showing which
  Spoke gateways are sending traffic directly to the Internet.
* Transit Egress: Displays VPC/VNets with Transit Egress enabled, where Spoke
  gateways forward traffic to a Transit gateway for Internet access.
* Monitored VPC/VNets: Displays VPC/VNets that are being monitored for egress
  traffic, allowing you to see which VPC/VNets have traffic flows logged at
  L4/L7.
* Unprotected VPC/VNets: Displays VPC/VNets that have direct access to the
  Internet without any egress protection applied.
* Unmanaged VPC/VNets: Displays VPC/VNets that are not yet onboarded or do not
  have Aviatrix gateways deployed within them.

<a id="end-help-egress-tab" />

## Related Topics

* <a href={"/docs/enterprise/" + "10.1" + "/reference/egress-filtering/egress-security-score"}>Overview of Egress Security Score Protection</a>
* [Egress Traffic Overview](https://legacy.docs.aviatrix.com/documentation/latest/security/egress-traffic-overview.html?expand=true)
* <a href={"/docs/enterprise/" + "10.1" + "/reference/security/egress/egress-security-score-calculated"}>Analysis of Egress Traffic</a>
