> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aviatrix.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Managing Firewalls in Transit FireNet

> FireNet supports three types of firewall vendors: Check Point CloudGuard, Fortinet FortiGate, and Palo Alto VM-Series. Panorama (firewall manager) is also supported for Palo Alto VM-Series firewalls.

FireNet supports three types of firewall vendors: Check Point CloudGuard,
Fortinet FortiGate, and Palo Alto VM-Series. Panorama (firewall manager) is also
supported for Palo Alto VM-Series firewalls.

After you <a href={"/docs/enterprise/" + "10.1" +
"/guides/security/firenet/firewall-launch-attach"}>deploy firewalls</a> you can
view them on the Security > FireNet > Firewall tab. You can deploy firewalls
from the Firewall tab, or you can
[import an existing cloud-deployed firewall](https://legacy.docs.aviatrix.com/documentation/latest/security/firewall-associate-existing.html).

From here you can also:

* <a href={"/docs/enterprise/" + "10.1" + "/guides/security/firenet/firewall-delete-disassociate"}>Disable or detach a firewall</a>

* Click the Management UI link to access the firewall UI and configure the
  firewall to check that FireNet traffic is flowing as expected. See the below
  examples for suggested configurations.

* Click the name of the firewall to view firewall details.

<Note>
  Any firewalls configured with password authentication do not allow for the
  downloading of the firewall access key.
</Note>

## Viewing Firewall Details

Click a firewall name on the Security > FireNet > Firewall tab to see its
details.

<img src="https://mintcdn.com/aviatrix-14b37c43/mOZ0lmP7pRPIryx3/images/guides/security/firenet/firenet-firewall-key.png?fit=max&auto=format&n=mOZ0lmP7pRPIryx3&q=85&s=fba70b12ae1e8b77325817c9c2bf7227" alt="firenet firewall key" width="2092" height="878" data-path="images/guides/security/firenet/firenet-firewall-key.png" />

You can click *Sync Routes to Firewall* to ensure that Transit FireNet routes
are synced to the selected firewall.

## Palo Alto

<Note>
  Palo Alto firewall versions greater than 9.1.3 are not supported in the GCP
  Transit FireNet configuration. When configuring{" "}
  <a href={"/docs/enterprise/" + "10.1" + "/reference/security/firenet/firewall-paloalto-configure-aws"}>Palo Alto for AWS</a>
  , you must download the access key to SSH into the firewall and change the
  password.
</Note>

<a href={"/docs/enterprise/" + "10.1" + "/reference/security/firenet/firewall-interfaces#paloalto-firewall-specs"}>Palo Alto firewall interface specifications</a>

<a href={"/docs/enterprise/" + "10.1" + "/reference/security/firenet/firewalls-supported-versions"}>Supported Palo Alto firewall versions</a>

You can use these example configuration documents to configure your Palo Alto
VM-Series firewall in the following clouds.

<Note>
  The Controller periodically issues Palo Alto API calls to find out if API can
  be issued successfully. This is used for route updating purposes, as firewall
  route updates requires API to work. If the Palo Alto API fails twice
  consecutively, the Controller declares the firewall is in Inaccessible state,
  but the firewall should still be attached and be able to forward traffic as
  long as its health checks pass.
</Note>

* <a href={"/docs/enterprise/" + "10.1" + "/reference/security/firenet/firewall-paloalto-configure-aws"}>Configuring Palo Alto for AWS</a>
* <a href={"/docs/enterprise/" + "10.1" + "/reference/security/firenet/firewall-paloalto-configure-azure"}>Configuring Palo Alto for Azure</a>
* <a href={"/docs/enterprise/" + "10.1" + "/reference/security/firenet/paloalto-vmseries-gcp"}>Configuring Palo Alto for GCP</a>
* <a href={"/docs/enterprise/" + "10.1" + "/reference/security/firenet/paloalto-vmseries-oci"}>Configuring Palo Alto for OCI</a>
* <a href={"/docs/enterprise/" + "10.1" + "/guides/security/firenet/firewall-panorama-configure"}>Configuring Panorama Firewall Manager for VM-Series</a>

## Fortinet FortiGate

<a href={"/docs/enterprise/" + "10.1" + "/reference/security/firenet/firewall-interfaces#fortigate-firewall-specs"}>FortiGate firewall interface specifications</a>

<a href={"/docs/enterprise/" + "10.1" + "/reference/security/firenet/firewalls-supported-versions"}>Supported Fortinet firewall versions</a>

You can use these example configuration documents to configure your Fortinet
FortiGate firewall in the following clouds.

* <a href={"/docs/enterprise/" + "10.1" + "/reference/security/firenet/fortigate-example-intro-aws"}>Configuring FortiGate for AWS</a>
* <a href={"/docs/enterprise/" + "10.1" + "/reference/security/firenet/fortigate-example-intro-azure"}>Configuring FortiGate for Azure</a>
* <a href={"/docs/enterprise/" + "10.1" + "/reference/security/firenet/config-fortigate-gcp"}>Configuring FortiGate for GCP</a>

## Check Point CloudGuard

<a href={"/docs/enterprise/" + "10.1" + "/reference/security/firenet/firewall-interfaces#checkpoint-firewall-specs"}>Check Point firewall interface specifications</a>

<a href={"/docs/enterprise/" + "10.1" + "/reference/security/firenet/firewalls-supported-versions"}>Supported Check Point firewall versions</a>

You can use these example configuration documents to configure your Check Point
CloudGuard firewall in the following clouds.

* <a href={"/docs/enterprise/" + "10.1" + "/guides/security/firenet/config-checkpoint"}>Deploying Check Point CloudGuard</a>
* <a href={"/docs/enterprise/" + "10.1" + "/reference/security/firenet/firewall-check-point-aws"}>Configuring Check Point for AWS</a>
* <a href={"/docs/enterprise/" + "10.1" + "/reference/security/firenet/firewall-check-point-azure"}>Configuring Check Point for Azure</a>

## Related Topics

* <a href={"/docs/enterprise/" + "10.1" + "/reference/security/firenet/firewalls-supported-versions"}>Supported Firewall Versions</a>
* <a href={"/docs/enterprise/" + "10.1" + "/reference/security/firenet/firewall-interfaces"}>Firewall Interface Specifications</a>
* <a href={"/docs/enterprise/" + "10.1" + "/reference/security/firenet/firenet-deployment-tgw"}>Aviatrix FireNet / AWS Transit Gateway Native Deployment Comparison</a>
* <a href={"/docs/enterprise/" + "10.1" + "/guides/security/firenet/firewall-subscribe-aws"}>Subscribing to a Firewall Instance (AWS)</a>
* <a href={"/docs/enterprise/" + "10.1" + "/guides/security/firenet/firewall-launch-attach"}>Deploying a Firewall</a>
* <a href={"/docs/enterprise/" + "10.1" + "/guides/security/firenet/firewall-delete-disassociate"}>Disassociating or Deleting Firewall Association</a>
* [Managing Firewall Attachments](https://legacy.docs.aviatrix.com/documentation/latest/security/firewall-manage-attachments.html)
* <a href={"/docs/enterprise/" + "10.1" + "/guides/security/firenet/firenet-health"}>Checking the Health of Your Firewall</a>
