> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aviatrix.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Configuring Transit FireNet

> With Aviatrix Transit FireNet you can insert firewalls into the Aviatrix Transit VPC/VNet for any supported cloud. Transit FireNet provides simplified firewall instance deployment and scaling, and allows the firewall instances to inspect East-West traffic (VPC/VNet to VPC/VNet), VPC/VNet to...

<a id="start-help-firenet-overview" />

With Aviatrix Transit FireNet you can insert firewalls into the Aviatrix Transit
VPC/VNet for any supported cloud. Transit FireNet provides simplified firewall
instance deployment and scaling, and allows the firewall instances to inspect
East-West traffic (VPC/VNet to VPC/VNet), VPC/VNet to Internet traffic (Egress),
and North-South traffic (VPC/VNet to on-prem).

<Note>
  Controller release 7.0.1577 or greater is required to use Transit FireNet in
  CoPilot. You can use FireNet in CoPilot to manage your existing Transit
  FireNet environment or build a new Transit FireNet environment.
</Note>

<a id="end-help-firenet-overview" />

<Note>
  Supported firewall vendors are Palo Alto VM-Series, Check Point CloudGuard,
  and Fortinet FortiGate. Panorama is also supported as an IPv4 firewall manager
  for Palo Alto VM-Series.
</Note>

<Note>
  Controller version 9.0 extends IPv6 FireNet vendor support to Fortinet and
  Check Point, in addition to Palo Alto Networks (supported from Controller
  version 8.2).
</Note>

The Security > FireNet > FireNet tab shows the Transit FireNets you have
created, along with their attached firewalls, if any connection polices have
been enabled (Inspection), and if Egress is enabled.

<img src="https://mintcdn.com/aviatrix-14b37c43/mOZ0lmP7pRPIryx3/images/guides/security/firenet/transit-firenet-tab.png?fit=max&auto=format&n=mOZ0lmP7pRPIryx3&q=85&s=6eabc0c84283df865076fb66b95f36de" alt="transit firenet tab" width="5110" height="1970" data-path="images/guides/security/firenet/transit-firenet-tab.png" />

## Transit FireNet Prerequisites

* If you want to attach Spokes to your Transit FireNet, you must
  [create the Spokes beforehand](https://legacy.docs.aviatrix.com/documentation/latest/network/spoke-gateway-about.html?expand=true).
* <a href={"/docs/enterprise/" + "10.1" + "/guides/security/firenet/firewall-subscribe-aws"}>Subscribe to the firewall instance (AWS only)</a>
  .
* GCP: a minimum of four VPCs (Transit FireNet VPC, Egress VPC, Management VPC,
  LAN VPC) is required for the GCP FireNet solution with the Palo Alto VM-Series
  firewall. All VPCs should be in the same region.
* Any Transit FireNet connections that use BGP over LAN must also have DNAT or
  SNAT configured.
* Transit Gateways cannot have network segmentation enabled.
* Transit Gateways cannot have any pre-existing attachments.

<Note>
  If desired, you can <a href={"/docs/enterprise/" + "10.1" +
  "/guides/platform-administration/vpc-vnet-create"}>create VPCs/VNets ahead of
  time</a> that have the *Transit + FireNet* VPC Function option selected,
  ensuring that the necessary subnets and interfaces are already created in those
  VPC/VNets in preparation for using the Transit FireNet feature. If when adding
  FireNet to a Transit gateway you decide to use a VPC/VNet that does not have the
  *Transit + FireNet* function selected, you must subsequently create the
  necessary subnets and interfaces in the relevant cloud service provider.
</Note>

## Workflow

1. [Add one or more FireNets](https://legacy.docs.aviatrix.com/documentation/latest/security/transit-firenet-create.html).
   You can create a standard Transit FireNet (where traffic is inspected), an
   [Egress FireNet](https://legacy.docs.aviatrix.com/documentation/latest/security/transit-firenet-create.html#egress-firenet),
   or an
   [AWS TGW FireNet](https://legacy.docs.aviatrix.com/documentation/latest/security/transit-firenet-create.html#aws-tgw-firenet).

   <Note>
     Creating a Transit FireNet automatically adds Transit Egress Capability to this Transit gateway. You can check this by going to Cloud Fabric > Gateways > Transit Gateways and clicking the name of the Transit FireNet you just created.
   </Note>

   After you create a Transit FireNet, you can select it on the FireNet tab and:

   * <a href={"/docs/enterprise/" + "10.1" + "/guides/security/firenet/firewall-launch-attach"}>View any attached firewalls</a>
   * View or
     [modify connection policies](https://legacy.docs.aviatrix.com/documentation/latest/security/transit-firenet-inspection-policy.html)
   * [View the FireNet VPC/VNet routing tables](https://legacy.docs.aviatrix.com/documentation/latest/security/transit-firenet-route-tables.html?expand=true)
   * View or
     [modify its settings](https://legacy.docs.aviatrix.com/documentation/latest/security/transit-firenet-settings.html)

2. <a href={"/docs/enterprise/" + "10.1" + "/guides/security/firenet/firewall-launch-attach"}>Add a firewall and associate it with a Transit FireNet</a>

3. [Associate an existing firewall with a Transit FireNet](https://legacy.docs.aviatrix.com/documentation/latest/security/firewall-associate-existing.html)

4. [Create connection policies for a FireNet](https://legacy.docs.aviatrix.com/documentation/latest/security/transit-firenet-inspection-policy.html)

5. <a href={"/docs/enterprise/" + "10.1" + "/guides/security/firenet/firenet-vendor-integration"}>Configure Vendor Integration (optional)</a>

   <Note>
     To turn On IPv6 on an existing FireNet, revoke the existing Vendor
     Integration settings, enable IPv6 on the FireNet, and then reconfigure
     Vendor Integration.
   </Note>

6. <a href={"/docs/enterprise/" + "10.1" + "/guides/security/firenet/transit-firenet-diagnostics"}>Run Transit FireNet diagnostics (optional)</a>

The following documents describe the available Cloud workflows:

* <a href={"/docs/enterprise/" + "10.1" + "/guides/security/firenet/transit-firenet-workflow-aws"}>Transit FireNet Workflow for AWS</a>
* <a href={"/docs/enterprise/" + "10.1" + "/guides/security/firenet/transit-firenet-workflow-aws-tgw"}>Transit FireNet Workflow for AWS TGW</a>
* <a href={"/docs/enterprise/" + "10.1" + "/guides/security/firenet/transit-firenet-workflow-azure"}>Transit FireNet Workflow for Azure</a>
* <a href={"/docs/enterprise/" + "10.1" + "/guides/security/firenet/transit-firenet-workflow-gcp"}>Transit FireNet Workflow for GCP</a>
* <a href={"/docs/enterprise/" + "10.1" + "/guides/security/firenet/transit-firenet-workflow-oci"}>Transit FireNet Workflow for OCI</a>

<a id="primary-secondary-firenet" />

## Primary and Secondary FireNet (AWS only)

In AWS (not AWS TGW) you can deploy a Transit FireNet architecture that consists
of one Primary and up to ten Secondary Transit FireNet gateways. This allows you
to scale to more than 125 HPE-enabled Spoke gateways and reduce the overall
number of firewall deployments.

The Primary FireNet is the Transit Gateway where firewalls are attached. This
FireNet can have its own Spoke Gateways and Site2Cloud or external connections.

Secondary FireNet Transit Gateways send traffic to the Primary FireNet to be
inspected by the firewall. A Secondary FireNet can only attach to one Primary
FireNet. Secondary FireNets can bypass Primary if the traffic does not require
inspection. Traffic that does not require inspection is routed to the closest
next hop.

### Prerequisites for Primary and Secondary FireNet

* [Segmentation](https://legacy.docs.aviatrix.com/documentation/latest/security/transit-firenet-settings.html/network-segmentation-secured)
  must be enabled on the gateways that will function as the Primary and
  Secondary FireNets before attachment occurs. You cannot enable segmentation
  after attachment.
* SNAT/NAT cannot be configured for the FireNets in a Primary/Secondary FireNet
  configuration.

### Prerequisites for Secondary FireNet

* GWLB cannot be enabled
* No firewalls attached
* No
  [egress static CIDR](https://legacy.docs.aviatrix.com/documentation/latest/security/transit-firenet-settings.html)
  configured
* No
  [exclude CIDR](https://legacy.docs.aviatrix.com/documentation/latest/security/transit-firenet-edit.html)
  configured
* Local ASN configured
* Network segmentation enabled

<Note>Secondary FireNet does not support IPv6.</Note>

## Related Topics

* <a href={"/docs/enterprise/" + "10.1" + "/concepts-architectures/architecture/security/firenet-design-patterns"}>FireNet Design Patterns</a>
* [Editing a Transit FireNet](https://legacy.docs.aviatrix.com/documentation/latest/security/transit-firenet-inspection-policy.html)
* <a href={"/docs/enterprise/" + "10.1" + "/guides/security/firenet/transit-firenet-attach-spoke"}>Attaching a Spoke to a Transit FireNet</a>
* [Configuring Transit FireNet Inspection Policies](https://legacy.docs.aviatrix.com/documentation/latest/security/transit-firenet-remove.html)
* [Removing Transit FireNet](https://legacy.docs.aviatrix.com/documentation/latest/security/transit-firenet-route-tables.html)
* [Viewing FireNet Route Table Information](https://legacy.docs.aviatrix.com/documentation/latest/security/firewall-manage-attachments.html)
* <a href={"/docs/enterprise/" + "10.1" + "/guides/security/firenet/firewall-delete-disassociate"}>Disassociating or Deleting Firewall Association</a>
* [Managing Firewall Attachments](https://legacy.docs.aviatrix.com/documentation/latest/security/firenet-test-connectivity.html)
* <a href={"/docs/enterprise/" + "10.1" + "/guides/security"}>Configuring your firewalls to check FireNet traffic flow</a>
