Controller
CoPilot
CoPilot Inbound Communication
For each Aviatrix gateway in your infrastructure:
- The CoPilot security group requires 2 rules: port 5000 for syslog and port 31283 for NetFlow.
- The Controller security group requires 1 rule: port 443.
CoPilot Outbound IP Addresses and Domains
Gateways
Aviatrix Edge Access
Aviatrix Edge access requirements fall into two rule sets: Aviatrix Edge Gateway access and Aviatrix Edge Platform access. Aviatrix Edge Gateway access rules are required for all deployments. Aviatrix Edge Platform access rules are additionally required when you deploy the Aviatrix Edge Gateway on a hardware device on which Aviatrix manages the software.Aviatrix Edge Gateway Access
The Aviatrix Edge Gateway requires outbound access to communicate with the Aviatrix Controller. Allow the following on your firewall:- MGMT: TCP 443 access to the Aviatrix Controller’s public IP address, if you use public connectivity for Edge Gateway management.
- MGMT: TCP 443 access to the Aviatrix Controller’s private IP address. Permit this access only if you selected Management over Private Network for management IP connectivity.
- WAN: UDP 500 and UDP 4500.
If you provide the management egress IP address for the Edge Gateway (for a
gateway that connects to the Controller over the public internet) when you
create the gateway, Aviatrix programs the required security rules on the
Controller’s gateway security group to allow the Edge Gateway to connect,
and programs the CoPilot security group with the NetFlow and syslog rules.If you do not know the management egress IP address when you create the Edge
Gateway, you can add it later. Aviatrix then adds the required rules to the
Controller’s and CoPilot’s security groups to allow the connection.You can also manage the Controller and CoPilot security groups yourself and add
the required rules to allow the Edge Gateway to connect to the Controller and
CoPilot.
Aviatrix Edge Platform Access
Aviatrix Edge Platform access is required in addition to Aviatrix Edge Gateway access when you deploy the Aviatrix Edge Gateway on a hardware device on which Aviatrix manages the software.Customer Management Access
Perform a DNS resolution for each destination FQDN listed in the tables on
this page. Although the listed IP addresses should not change, Aviatrix
recommends keeping IP-based rules up to date.