Skip to main content
To ensure optimal functionality of Aviatrix products, allow access to the following external sites and configure access to a DNS server for successful name resolution. These requirements apply to the Aviatrix Controller, gateways, CoPilot, and Aviatrix Edge. In most cases, Aviatrix automatically provisions these configurations during deployment.

Controller

CoPilot

CoPilot Inbound Communication

For each Aviatrix gateway in your infrastructure:
  • The CoPilot security group requires 2 rules: port 5000 for syslog and port 31283 for NetFlow.
  • The Controller security group requires 1 rule: port 443.
For example, an infrastructure with 100 gateways requires 200 security group rules on CoPilot and 100 security group rules on the Controller.
CoPilot Security Group Management can automate these inbound rules instead of requiring you to add them manually. See CoPilot Security Group Management .

CoPilot Outbound IP Addresses and Domains

Gateways

Aviatrix Edge Access

Aviatrix Edge access requirements fall into two rule sets: Aviatrix Edge Gateway access and Aviatrix Edge Platform access. Aviatrix Edge Gateway access rules are required for all deployments. Aviatrix Edge Platform access rules are additionally required when you deploy the Aviatrix Edge Gateway on a hardware device on which Aviatrix manages the software.

Aviatrix Edge Gateway Access

The Aviatrix Edge Gateway requires outbound access to communicate with the Aviatrix Controller. Allow the following on your firewall:
  1. MGMT: TCP 443 access to the Aviatrix Controller’s public IP address, if you use public connectivity for Edge Gateway management.
  2. MGMT: TCP 443 access to the Aviatrix Controller’s private IP address. Permit this access only if you selected Management over Private Network for management IP connectivity.
  3. WAN: UDP 500 and UDP 4500.
If you provide the management egress IP address for the Edge Gateway (for a gateway that connects to the Controller over the public internet) when you create the gateway, Aviatrix programs the required security rules on the Controller’s gateway security group to allow the Edge Gateway to connect, and programs the CoPilot security group with the NetFlow and syslog rules.If you do not know the management egress IP address when you create the Edge Gateway, you can add it later. Aviatrix then adds the required rules to the Controller’s and CoPilot’s security groups to allow the connection.You can also manage the Controller and CoPilot security groups yourself and add the required rules to allow the Edge Gateway to connect to the Controller and CoPilot.

Aviatrix Edge Platform Access

Aviatrix Edge Platform access is required in addition to Aviatrix Edge Gateway access when you deploy the Aviatrix Edge Gateway on a hardware device on which Aviatrix manages the software.

Customer Management Access

Perform a DNS resolution for each destination FQDN listed in the tables on this page. Although the listed IP addresses should not change, Aviatrix recommends keeping IP-based rules up to date.
Applies to all Aviatrix Controller versions.