> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aviatrix.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Aviatrix Glossary

> This Glossary provides definitions of Aviatrix products, features, tools, and general terminology.

This Glossary provides definitions of Aviatrix products, features, tools, and
general terminology.

## ACE (Aviatrix Certified Engineer) Training

The Aviatrix Certified Engineer (ACE) program is a multicloud networking and
security certification available to technical professionals and cloud
practitioners. The program offers an overview of the networking industry's move
from on-premises to cloud servers, the main cloud service providers (AWS, Azure,
GCP, and OCI) and their platforms, the necessity of multicloud networking
architecture, and case studies that demonstrate how multicloud networking
architecture has benefited specific customers.

## ActiveMesh

ActiveMesh is an Aviatrix networking architecture that provides a
highly-available and scalable encrypted transit network for cloud environments.
It is based on a load balancing model where both primary and backup gateways
forward packets, thus improving network performance and resiliency. This
architecture ensures that the network remains highly available and resilient. In
ActiveMesh mode, multiple remotes sites can be connected to the Aviatrix Transit
gateways.

<a id="appiq" />

## AppIQ

Aviatrix AppIQ shows network and domain traffic between any two cloud instances
that are connected via your Aviatrix Transit network.

<a id="attachment-point" />

## Attachment Point

An Attachment Point is a reserved placeholder in the policy structure. It
enables higher-level administrators to create attachment points where
lower-level teams can add their own policy groups. The order of creation does
not matter—an existing policy group can link to an attachment point before that
point is created. Attachment point names must be globally unique.

## Auto Right-Sizing

The Auto Right-Sizing feature enables the deployment of appropriately sized
gateways, ensuring optimized cloud spending. By monitoring traffic patterns, the
feature provides recommendations for resizing gateways that are either too small
to handle the observed traffic or are oversized and increase cloud costs.

<Note>
  Aviatrix recommends using the Auto Right-Sizing feature instead of Gateway
  Scaling (if you configured Gateway Scaling prior to CoPilot 4.15), unless you
  need to schedule gateway resizing or want to add new gateway instances when
  scaling up.
</Note>

<a id="avx-billing" />

## Aviatrix Billing

Aviatrix Billing enables you to analyze the costs of your Aviatrix Controller
and gateways. You can review your account's Total Cost and review costs by Cloud
Service Provider, region, group of Cloud Accounts, and individual Cloud Account.

## Aviatrix Cloud Fabric

The network managed by the Aviatrix Cloud Networking Platform, the network data
plane. Aviatrix Cloud Fabric includes telemetry and distributed controls
embedded in the network data plane to deliver advanced networking, Distributed
Cloud Firewall, and enterprise-class visibility and troubleshooting.

## Aviatrix Cloud Networking License Service

A service from Aviatrix that provides licenses and customer IDs needed to access
Aviatrix Cloud Network Controller and Aviatrix Cloud Network CoPilot.

<a id="avx-cloud-networking-platform" />

## Aviatrix Cloud Networking Platform

The Aviatrix Cloud Networking Platform is a management and control plane or a
single pane of glass that enables you to manage and support a single or
multicloud network architecture. You can deploy an Aviatrix Cloud Networking
Platform, or Aviatrix Controller & CoPilot, through any of the four major Cloud
Service Provider marketplaces.

## Aviatrix Controller

A cloud instance of the Aviatrix software that processes network operations. The
Controller manages connections, gateways, users, security, and other networking
operations.

## Aviatrix CoPilot

CoPilot is the Aviatrix software GUI used to configure all your network
connections, policies, and monitor all gateways and traffic on your network.
Customizable monitoring tools give you views of network resource usage,
performance, security threats, and financial data.

## Aviatrix License (customer ID)

A license from Aviatrix that allows users to access and use their software and
services. Aviatrix licenses can be obtained through the Aviatrix Cloud
Networking License Service.

## AWS Marketplace Listing

A public listing on AWS Marketplace where customers can find, buy, and deploy
software and services. It includes product information, pricing, and usage
instructions. The counterpart on Azure is the
[Azure Marketplace Offer](#azure-marketplace-offer).

## AWS Transit Gateway Orchestrator

Aviatrix AWS TGW (Transit Gateway) Network Orchestration creates a single hub
for transit networks across multiple AWS regions. The AWS TGW feature in
Aviatrix CoPilot connects your Aviatrix platform to this AWS feature and enables
you to attach Spoke VPCs to your Aviatrix Transit Network.

## Aviatrix VPN Client

The Aviatrix VPN Client provides SAML authentication for VPN users.

<a id="azure-marketplace" />

## Azure Marketplace Offer

Offers on the Azure Marketplace where customers can buy and deploy applications
and services on Azure. These offers include product descriptions, pricing, and
deployment instructions.

## BYOL (Bring Your Own License)

A licensing model where customers can use software licenses issued by Aviatrix
License Service to activate and use in a new environment, like the cloud,
allowing for cost savings and flexibility. Both Aviatrix Cloud Network
Controller and Aviatrix Cloud Network CoPilot use the BYOL licensing model.

## Cloud Fabric™

The network managed by the Aviatrix Cloud Networking Platform, the network data
plane. Aviatrix Cloud Fabric includes telemetry and distributed controls
embedded in the network data plane to deliver advanced networking, Distributed
Cloud Firewall, and enterprise-class visibility and troubleshooting.

## CloudN

CloudN is a 1U rack mountable hardware appliance deployed in the datacenter. It
works with the Aviatrix gateway.

CloudN is being replaced by [Edge Networking](#edge-networking).

## Cloud Network Backbone

The Aviatrix Cloud Network Backbone is created when Aviatrix brings all your
enterprise network resources together to create a resilient and secure cloud
backbone using a hub-and-spoke topology. After deploying an Aviatrix software
instance in AWS, Azure, or GCP you can begin to create Aviatrix transit gateways
in one or more cloud service providers to form the core of your cloud network.
AWS and GCP virtual private clouds (VPCs), Azure virtual networks (VNets), and
OCI virtual cloud networks (VCNs) can then seamlessly integrate into your
Aviatrix Cloud Network Backbone.

## Cloud Networking

The network managed by the Aviatrix Cloud Networking software including
connections between users, devices, cloud native services and applications.
Security is built into every level of your Aviatrix network with Aviatrix
high-performance encryption (HPE), ThreatIQ monitoring, and Distributed Cloud
Firewall.

## Cloud Security

Cloud security encompasses a broad spectrum of policies, technologies,
applications, and controls deployed to protect cloud-based systems, data, and
infrastructure. From authenticating access to filtering traffic, cloud security
can be tailored to the unique needs of the business. The flexibility of cloud
security solutions enables businesses to deploy them on-premises, in the cloud,
or a hybrid model, offering protection across various cloud services and
infrastructure.

For more information see
[https://aviatrix.com/learn-center/cloud-security/](https://aviatrix.com/learn-center/cloud-security/).

## Connected Transit

The Connected Transit feature enables you to build a full mesh network where
Spoke VPC/VNets can communicate with each other via the Transit Gateway.

<a id="costiq" />

## CostIQ

Aviatrix CostIQ offers visibility into costs of resources across all clouds in
your multicloud network that are managed by Aviatrix Controller. This feature
provides visibility into shared services used by cost centers for bill back
purposes. CostIQ is a feature that must be enabled by application
administrators.

<a id="dcf" />

## Distributed Cloud Firewall (DCF)

Aviatrix Distributed Cloud Firewall embeds Layer 4-7 network security on top of
the Aviatrix Cloud Networking infrastructure. Advanced security capabilities
include Layer 4 visibility and policy enforcement, URL/FQDN filtering (formerly
Egress FQDN Filtering), reputation-based Threat Detection/Prevention (ThreatIQ),
transparent MITM decryption, and Advanced Threat Detection with Suricata.
Micro-segmentation (intra-VNet/VPC segmentation) can be enabled on VPC/VNets to
enforce greater granular segmentation policies.

<a id="edge-gateway" />

## Edge Gateway

An Aviatrix gateway that enables connectivity to edge locations such as data
centers, co-locations, remote sites, provider locations, branch offices, and
retail stores.

<a id="edge-networking" />

## Edge Networking

The hardware/virtual appliance provided by Aviatrix as an alternative to SDWAN
solutions (formerly known as CloudN or ExoGateway). Aviatrix Edge connects
different Cloud Service Provider networks in its multicloud networking
architecture framework.

<a id="egress-fqdn-filtering" />

## Egress FQDN Filtering (Legacy)

Secures VPC/VNet/VCN Egress by filtering outbound traffic to the Internet. This
feature enables companies to discover what Internet sites their cloud apps are
communicating with, push filtering policies instantly to one VPC or hundreds of
VPCs, move from NAT Gateway (IP address based) to Fully Qualified Domain Name
(FQDN) filtering, and audit all events, including the packets.

You can view Egress FQDN filtering in the Aviatrix Controller, Aviatrix CoPilot,
or by exporting logs.

<a id="egress-gateway" />

## Egress Gateway

An Aviatrix gateway that performs the function of cloud-to-Internet egress
filtering and egress security. Connectivity between a VPC/VNet and the Internet.

<a id="external-group" />

## ExternalGroups

An ExternalGroup refers to groups of external IP sources that can be used with
Distributed Cloud Firewall for enforcement. Examples of external groups are:

* SaaS-based Services such as Azure and GitHub (CoPilot 4.17 and greater)
* Countries and Threat Feeds (CoPilot 4.17 or greater)
* ThreatGroups and GeoGroups (Controller version 7.2.4820)
* ThreatIQ and Geoblocking (prior to Controller version 7.2.4820)

## FlowIQ

Aviatrix CoPilot's dynamic topology mapping, which helps companies maintain an
accurate view of their global multicloud networks. FlowIQ helps you analyze
global network traffic flows using global heat maps and time series trend charts
to easily pinpoint and troubleshoot traffic anomalies.

## Gateway

An Aviatrix gateway is a virtual router managed by Aviatrix. It routes traffic
in accordance with the connection and security policies you define in the
Aviatrix Cloud Networking Platform. See the definitions of the Gateway types:
[Egress Gateway](#egress-gateway), [Edge Gateway](#edge-gateway),
[Spoke Gateway](#spoke-gateway), and [Transit Gateway](#transit-gateway).

## Gateway High Availability

Aviatrix Gateway High Availability supports multiple gateway instances in a VPC
or VNet for high availability and scalability, to minimize and reduce network
downtime and improve network stability and performance to mitigate packet loss.

<a id="gateway-scaling" />

## Gateway Scaling

<Note>
  The Gateway Scaling tabs are only displayed if you configured Gateway Scaling
  prior to CoPilot 4.15.
</Note>

Aviatrix Gateway Scaling helps ensure that appropriate sizing is applied to
VPC/VNets on AWS and Azure Spoke gateways. This can reduce cloud provider costs,
improve performance and mitigate packet loss. You can apply manual, automatic,
or scheduled scaling to your selected VPC/VNets.

## High Performance Encryption (HPE)

Aviatrix High Performance Encryption (HPE) enables 10Gbps and higher IPsec
performance between two single Aviatrix Gateway instances, or between a single
Aviatrix Gateway instance and on-premises Aviatrix appliance. Multiple tunnels
are established between two virtual routers, allowing all CPU cores to be used
for performance scaling with the CPU resources.

Formerly known as "Insane Mode".

## Horizontal Gateway Scaling

With Gateway Scaling you can add or remove gateway instances to support the
increased or decreased traffic (horizontal scaling).

Also see [Gateway Scaling](#gateway-scaling).

<Note>
  The Gateway Scaling tabs are only displayed if you configured Gateway Scaling
  prior to CoPilot 4.15.
</Note>

## Migration

Refers to data migration and appliance migration. The data migration refers to
migrating data from one instance to another instance. The appliance migration
usually refers to migrating a deployment, which includes a new deployment and
data migration.

## Multicloud Transit Network Architecture

Aviatrix Multicloud Transit Network architecture is about building connectivity
between the cloud and on-premises in the most agile manner possible. In the
Aviatrix Multicloud Transit Network architecture, there is one connection (not
including the backup) between on-premises and a Transit VPC or VNet. Everything
else (the Spoke VPC and VNets to on-premises traffic) is routed through the
Transit VPC or VNet.

## Multicloud Transit Segmentation

Aviatrix Multicloud Transit Segmentation provides network isolation and enhanced
security through network domains and connection policies to the Aviatrix
Multicloud Transit Network, where both Spoke and Transit networks deploy
Aviatrix Gateways across multi-region and multicloud.

## Multi-Tier Transit

Use the Multi-Tier Transit setting to implement a hierarchical Transit Gateway
architecture that permits packets to traverse more than two Aviatrix Transit
Gateways. You can connect two cloud service providers or regions through one
peered connection. You must implement ActiveMesh to use multi-tier transit
gateways, but full-mesh transit peering is not required.

## NAT Gateway

An Aviatrix gateway that performs the network address translation (NAT)
function.

<a id="policy-group" />

## PolicyGroup

A PolicyGroup is a logical container that bundles multiple rulesets or policy
groups. It enables consistent security posture across multiple accounts, VPCs,
or environments.

## Private Mode

Private Mode is a global setting that offers secure orchestrated intra- and
multicloud networking by removing the need for public IPs for Aviatrix gateways.
Web proxies are used for the gateways to access the internet. All communication
is done via native cloud constructs such as Load Balancers, Private Link
Services, and peering connections, which act as the underlay for the Aviatrix
Transit Network.

Private Mode has been removed as of Controller 10.1.0. Gateways can instead be
deployed without a public IP address using Aviatrix's per-gateway
private-IP-only configuration option.

## Public Subnet Filtering Gateway

An Aviatrix gateway that provides ingress and egress security for AWS public
subnets where instances have public IP addresses.

## Rollback

Rollback refers to the process of reverting a system or application to a
previous version, usually after encountering errors during an upgrade.
Currently, Aviatrix supports Gateway Rollback.

<a id="rule-dcf" />

## Rule

A Rule is the most granular unit in Distributed Cloud Firewall (DCF). It defines
a specific traffic control action (permit or deny) based on criteria like
source/destination IPs, ports, protocols, and SmartGroups. Each rule has a
priority value that determines evaluation order within a ruleset.

<a id="ruleset-dcf" />

## Ruleset

A Ruleset is an ordered collection of DCF rules. It allows logical grouping of
rules based on function, environment, geography, application, or other criteria.
Each ruleset has a unique priority range (typically 1000-8999) and is evaluated
in priority order.

## Gateway Rollback

The gateway rollback replaces the current gateway instance with a new instance
using the previous Controller software version, with the gateway base image
aligned to that version. Sometimes, the gateway base image remains the same
across software versions, but the gateway instance is still replaced even if the
base image has not changed. This rollback is required when the current gateway
encounters software compatibility issues.

## Security Group Management

Use Security Group Management to manage inbound gateway rules.

## Security Group Orchestration

This feature utilizes cloud-native security features (such as network and
application security groups within Azure, and security groups within AWS) to
provide security control within the virtual network. Based on the SmartGroup and
[Distributed Cloud Firewall (DCF)](#distributed-cloud-firewall-dcf) policy rule
configuration, Aviatrix will push these security group policies to provide L4
access control for the workloads in the virtual network.

## Site2Cloud (External Connection)

Site2Cloud builds an encrypted connection between two sites over the Internet in
a template-driven manner. On one end of the tunnel is an Aviatrix Gateway. The
other end could be an on-premises router, firewall, or another public cloud
VPC/VNet, that the Aviatrix Controller does not manage.

## SmartGroups

A SmartGroup is a logical grouping of your resources that are managed by
Aviatrix. The grouping of resources may represent various departments, business
units, or other aspects of your organization based on how you group your
resources.

## Specialty Gateway

An Aviatrix gateway that is not a Transit or Spoke gateway (for example, a
Public Subnet Filtering, NAT, or standalone gateway).

<a id="spoke-gateway" />

## Spoke Gateway

In Aviatrix's Hub-and-Spoke topology, a Spoke Gateway connects components within
the same Cloud Service Provider main account or tenancy.

## ThreatIQ

Aviatrix CoPilot feature that enables you to monitor for security threats in
your Aviatrix cloud network, set alerts when threats are detected in the network
traffic flows, and block traffic that is associated with threats. All of these
capabilities apply to your entire cloud network (multicloud or single cloud)
that is managed by Aviatrix Controller.

## Transit FireNet

A turnkey or ready-made network solution to deploy firewall instances in the
cloud. Transit FireNet significantly simplifies firewall instance deployment and
allows the firewall instances to inspect traffic between VPC/VNets/VCNs traffic
(East West), between VPC/VNets/VCNs and the Internet traffic (Egress), and
VPC/VNet/VCN to on-premises traffic (North South).

Transit FireNet also allows you to scale firewall deployment to multiple
Availability Zones and multi-instances so that your network can grow with your
company.

<a id="transit-gateway" />

## Transit Gateway

In Aviatrix's Hub-and-Spoke Topology, a Transit Gateway connects a company's
subnets across the main Cloud Service Providers: AWS, Azure, GCP and OCI. This
Transit Gateway connection provides high-speed and secure data transfers between
networks while allowing for traffic engineering and multi-account subscription
monitoring.

## Transit Gateway Peering

Aviatrix Transit Gateway Peering connects two or more Aviatrix Transit Gateways
in a partial or full-mesh manner for communication between groups of Spoke VPCs
or VNets across multiple clouds and regions.

## Upgrade

Upgrade is used for / often refers (in the context of) to Aviatrix Platform,
Controller, CoPilot (Software Updates).

Aviatrix supports the following types of upgrade:

* **Software Upgrade (Controller and Gateway)**: Update the Aviatrix software
  without creating new instances. This software upgrades replace the relevant
  Aviatrix Controller and gateway packages, configuration files, and binaries
  without disrupting network traffic or replacing the gateways. The software
  upgrade causes minimal disruption to network traffic.

* **Controller Image Upgrade**: Updates the base image of the controller, which
  is needed for operating system or kernel upgrades and may include an Aviatrix
  software upgrade. This results in minimal disruption to network traffic.

* **Gateway Image Upgrade**: Updates the base image of the gateway, potentially
  causing brief traffic disruptions. To minimize impact, deploying gateways with
  high availability (HA) is recommended, and upgrades should be performed on one
  gateway at a time within the HA set. Gateway image upgrades are usually
  required after a Controller Image Upgrade to ensure that the Aviatrix Platform
  and gateways are operating with the same base software version.

## URL/FQDN Filtering

Secures VPC/VNet/VCN Egress by filtering outbound traffic to the Internet. This
feature enables companies to discover what Internet sites their cloud apps are
communicating with, push filtering policies instantly to one VPC or hundreds of
VPCs, move from NAT Gateway (IP address based) to Fully Qualified Domain Name
(FQDN) filtering, and audit all events, including the packets.

You can view URL/FQDN filtering in Aviatrix CoPilot, or by exporting logs.

Also see [Distributed Cloud Firewall (DCF)](#distributed-cloud-firewall-dcf) and
[WebGroups](#webgroups).

## UserVPN

The Aviatrix UserVPN feature is a client VPN solution based on OpenVPN® that is
compatible with all OpenVPN® clients.

## Vertical Gateway Scaling

With Gateway Scaling you can scale the gateways vertically (increase or decrease
gateway size) to support increased or decreased gateway traffic.

Also see [Gateway Scaling](#gateway-scaling).

<Note>
  The Gateway Scaling tabs are only displayed if you configured Gateway Scaling
  prior to CoPilot 4.15.
</Note>

## VPN Gateway

An Aviatrix gateway that performs the function of VPN connectivity between your
partners/branches and your cloud services for site-to-cloud VPN access (deployed
on the partner/branch side), or VPN connectivity between your remote users and
the cloud for dynamic enforcement, to differentiate the users connecting into
the cloud. This is useful for companies that have no on-premises data center
(all resources are in the cloud).

<a id="webgroups" />

## WebGroups

WebGroups define Domains and URLs into a group which can be used in the
Distributed Firewalling Rules as a matching condition for the Rule action to be
enforced.
