> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aviatrix.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Firewall Interface Specifications

> Palo Alto firewall versions greater than 9.1.3 are supported in the GCP Transit FireNet configuration if you select one of the available Flex Next-Generation firewall options.

<a id="checkpoint-firewall-specs" />

## Check Point Specifications

| Cloud Provider | Check Point VM Instance Interfaces                                                        | Description                                                                                                              | Inbound Security Group Rule                                                                                                        |
| -------------- | ----------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------- |
| AWS            | eth0 (on subnet -Public-FW-ingress-egress-AZ-a)<br /><br />eth1 (on subnet -dmz-firewall) | Egress or Untrusted Interface (Egress Interface is used as the management interface)<br /><br />LAN or Trusted Interface | Controller version lower than 7.0.1577: Allow ALL from 0.0.0.0/0<br /><br />Controller version 7.0.1577 and above: TCP 443, TCP 22 |
| Azure          | eth0 (on subnet -Public-FW-ingress-egress)<br /><br />eth1 (on subnet -dmz-firewall)      | Egress or Untrusted Interface<br /><br />LAN or Trusted Interface                                                        | Allow ALL<br /><br />Allow ALL (do not change)                                                                                     |

<a id="fortigate-firewall-specs" />

## FortiGate Specifications

| Cloud Provider | FortiGate VM Interfaces                                                                   | Description                                                       | Inbound Security Group Rule                                                                                                                                        |
| -------------- | ----------------------------------------------------------------------------------------- | ----------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| AWS            | eth0 (on subnet -Public-FW-ingress-egress-AZ-a)<br /><br />eth1 (on subnet -dmz-firewall) | Egress or Untrusted Interface<br /><br />LAN or Trusted Interface | Controller version lower than 7.0.1577: Allow ALL<br /><br />Controller version 7.0.1577 and higher: TCP 443 is allowed from the Controller's public or private IP |
| Azure          | eth0 (on subnet -Public-FW-ingress-egress)<br /><br />eth1 (on subnet -dmz-firewall)      | Egress or Untrusted Interface<br /><br />LAN or Trusted Interface | Allow ALL<br /><br />Allow ALL (do not change)                                                                                                                     |

<a id="paloalto-firewall-specs" />

## Palo Alto Specifications

<Note>
  Palo Alto firewall versions greater than 9.1.3 are supported in the GCP
  Transit FireNet configuration if you select one of the available Flex
  Next-Generation firewall options.
</Note>

| Cloud Provider | Palo Alto VM Interfaces                                                                                                                                      | Description                                                                                       | Inbound Security Group Rule                                                                   |
| -------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------- |
| AWS            | eth0 (on subnet -Public-FW-ingress-egress-AZ-a)<br /><br />eth1 (on subnet -Public-gateway-and-firewall-mgmt-AZ-a)<br /><br />eth2 (on subnet -dmz-firewall) | Egress or Untrusted Interface<br /><br />Management Interface<br /><br />LAN or Trusted Interface | Allow ALL<br /><br />Controller version lower than 7.0.1577: Allow SSH, HTTPS, ICMP, TCP 3978 |
| Azure          | eth0 (on subnet -Public-gateway-and-firewall-mgmt)<br /><br />eth1 (on subnet -Public-FW-ingress-egress)<br /><br />eth2 (on subnet -dmz-firewall)           | Management Interface<br /><br />Egress or Untrusted Interface<br /><br />LAN or Trusted Interface | Allow SSH, HTTPS, ICMP, TCP 3978<br /><br />Allow ALL<br /><br />Allow ALL (do not change)    |
| GCP            | nic0<br /><br />nic1<br /><br />nic2                                                                                                                         | Egress or Untrusted Interface<br /><br />Management Interface<br /><br />LAN or Trusted Interface | Allow ALL<br /><br />Allow SSH, HTTPS, ICMP, TCP 3978<br /><br />Allow ALL (do not change)    |

<a href={"/docs/enterprise/" + "10.1" + "/reference/security/firenet/firewalls-supported-versions"}>Supported Firewall Versions</a>

<a href={"/docs/enterprise/" + "10.1" + "/reference/security/firenet/firenet-deployment-tgw"}>Aviatrix FireNet / AWS Transit Gateway Native Deployment Comparison</a>
