> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aviatrix.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Hybrid Cloud

> This section provides the purpose, elements, and actions performed on the Hybrid Cloud pages.

This section provides the purpose, elements, and actions performed on the
**Hybrid Cloud** pages.

<Tabs>
  <Tab title="Overview">
    ## Purpose

    The **Overview** page provides a high-level view of hybrid connectivity components, including Edge Gateways, on-premises devices, and integrated platforms for extending Aviatrix networking into private data centers.

    ## Elements

    <Frame>
      <img src={"/images/reference/ui/cloud-fabric/hybrid-overview.png"} alt="Hybrid Cloud: Overview" width="100%" />
    </Frame>

    * **Edge Gateways count**: Displays count and health status of deployed Edge Gateways (e.g., "33 Down" indicates 33 Edge Gateways are currently down).
    * **Edge Gateways canvas**: An interactive topology map that shows the logical and physical views of Edge Gateways connecting cloud and on-premises environments.
    * **View in Topology button**: Opens the Topology canvas focused on hybrid connectivity components.
    * **Legend button**: Toggles the display of legend information for the topology map.
    * **Truncate Labels toggle**: Controls whether labels on the topology map are truncated or shown in full.

    ## Actions

    <AccordionGroup>
      <Accordion title="View Overview">
        To view the Hybrid Cloud Overview page and hybrid connectivity components:

        1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Overview**.<br />The Overview page appears with Edge Gateways count, health status, and an interactive topology map showing Edge Gateways, on-premises devices, and platform integrations.
        2. Optionally, switch between logical and physical views on the canvas.
        3. Optionally, click **Legend** to show or hide legend information.
        4. Optionally, use **Truncate Labels** to truncate or show full labels on the map.

        The Overview page displays the hybrid connectivity components and their status.

        ### Parameter Details

        | CoPilot Parameter Name | Description                                                             |
        | ---------------------- | ----------------------------------------------------------------------- |
        | Edge Gateways Count    | Shows the total number of deployed Edge Gateways and how many are down. |
        | Connected Devices      | Shows the number of onboarded devices for hybrid connectivity.          |
        | Platform Integrations  | Lists integrated platforms (for example, VMware, Nutanix).              |
        | Health Status          | Indicates the operational health of hybrid components.                  |
      </Accordion>

      <Accordion title="View in Topology">
        To open the Topology canvas focused on hybrid connectivity:

        1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Overview**.<br />The Overview page appears with the Edge Gateways canvas.
        2. Click **View in Topology**.

        The Topology page opens with the map focused on hybrid connectivity components (Edge Gateways, devices, and platform integrations).
      </Accordion>
    </AccordionGroup>
  </Tab>

  <Tab title="Edge Gateways">
    <Tabs>
      <Tab title="Spoke Gateways">
        ## Purpose

        The **Spoke Gateways** page shows a table of Edge Spoke Gateways deployed for hybrid connectivity and their configurations and statuses.

        ## Elements

        <Frame>
          <img src={"/images/reference/ui/cloud-fabric/hybrid-edge-spoke.png"} alt="Hybrid Cloud: Edge Spoke Gateways" width="100%" />
        </Frame>

        * **+ Spoke Gateway button**: Starts workflow to deploy a new Edge Spoke Gateway.
        * **Edge Spoke Gateway table**: Displays Edge Spoke Gateway name, Platform type, Site, Device, Private IP, Transit Gateway, and Status.
        * **Edit button**: Opens configuration panel to modify Edge Spoke Gateway settings.
        * **Manage Gateway Attachments button**: Opens a panel to manage the Edge Spoke Gateway attachments.
        * **Actions menu**: Manage NAT mappings on the Gateway interface.
        * **Delete button**: Deletes the selected Edge Spoke Gateway.
        * **Show filters button**: Opens filter options for the table.
        * **Select columns button**: Configures visible table columns.
        * **Export button**: Exports table data.
        * **Search box**: Search box for filtering table content.
        * **Refresh button**: Refreshes table data.

        **Create Spoke Gateway wizard**

        * **Step 1: Gateway Configuration**: Name, Platform, Site, High availability, Device(s), Gateway Resource Size, ZTP file type.
        * **Step 2: Interface Configuration**: WAN, LAN, and MGMT interfaces. See Create Edge Spoke Gateway accordions for platform-specific steps.

        <Frame>
          <img src={"/images/reference/ui/cloud-fabric/hybrid-edge-spoke-create-1.png"} alt="Hybrid Cloud: Create Edge Spoke Gateway - Step 1" width="100%" />
        </Frame>

        <Frame>
          <img src={"/images/reference/ui/cloud-fabric/hybrid-edge-spoke-create-2.png"} alt="Hybrid Cloud: Create Edge Spoke Gateway - Step 2" width="100%" />
        </Frame>

        ## Actions

        <AccordionGroup>
          <Accordion title="Configure Edge Spoke Gateway">
            <Accordion title="View Edge Spoke Gateways">
              To view the list of Edge Spoke Gateways and their details:

              1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Edge Gateways** > **Spoke Gateways**.<br />The Spoke Gateways page appears with a table of Edge Spoke Gateways.
              2. Optionally, use the **Search** field, **Filter** icon, **Select columns**, or **Export** to find or export data.
              3. Click an Edge Spoke Gateway name to view its details.

              The table displays the list of Edge Spoke Gateways with their configurations and status.

              ### Parameter Details

              | CoPilot Parameter Name      | Description                                                                                   |
              | --------------------------- | --------------------------------------------------------------------------------------------- |
              | Name                        | Shows the name of the Edge Spoke Gateway.                                                     |
              | Platform Type               | Shows the platform type (AEP, Equinix, Self managed, Megaport) where the gateway is deployed. |
              | Site                        | Shows the site where the Spoke Gateway is deployed.                                           |
              | Device                      | Shows the device associated with the Spoke Gateway.                                           |
              | Private IP                  | Shows the private IP address of the Spoke Gateway.                                            |
              | Transit Gateway Attachments | Shows the number or list of attached Transit Gateways.                                        |
              | Status                      | Shows the current status of the Spoke Gateway.                                                |
            </Accordion>

            <Accordion title="Create Edge Spoke Gateway (AEP)">
              To create an Edge Spoke Gateway on the Aviatrix Edge Platform:

              1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Edge Gateways** > **Spoke Gateways**.<br />A table appears with the list of Edge Spoke Gateways.
              2. Click **+ Spoke Gateway**.<br />The Create Edge Spoke Gateway wizard appears.
              3. In **Step 1: Gateway Configuration**, provide Name, Platform, Site, High availability, Primary Device, Secondary Device (if HA), and Gateway Resource Size. Refer to the AEP Parameter Details table.
              4. Click **Next**.
              5. In **Step 2: Interface Configuration**, click **WAN** and configure the WAN interface (Interface, IP assignment, Interface labels, Interface CIDR, Default gateway IP, Public IP).
              6. Click **LAN** and configure the LAN interface. Optionally, click **+ VLAN Interface** to add VLAN sub-interfaces.
              7. Click **MGMT** and configure the Management interface.
              8. Click **Create** or **Save**.

              A notification appears when the Edge Spoke Gateway is created. Verify the gateway creation from the Spoke Gateways table.

              ### Parameter Details

              **Step 1: Gateway Configuration**

              | CoPilot Parameter Name | Description                                                                                                                                       |
              | ---------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------- |
              | Name                   | Enter a unique name for the edge gateway. The name starts with a letter and uses letters, numbers, and dashes only.                               |
              | Platform               | Select the platform account where the edge gateway runs.                                                                                          |
              | Site                   | Enter a name or select from the list that identifies the on-premises location.                                                                    |
              | High availability      | Turn **Off** for primary only. Turn **On** (Active-Standby) for one active and one standby peering. Turn **On** (Active-Active) for load sharing. |
              | Preemptive             | (Active-Standby only) Turn **On** to switch back to primary when it recovers. Turn **Off** to stay on standby until manual switchover.            |
              | Primary Device         | Select the edge device for the primary Edge Gateway.                                                                                              |
              | Secondary Device       | Select the edge device for the secondary (HA) Edge Gateway.                                                                                       |
              | Gateway Resource Size  | Small (2 vCPU, 4GB), Medium (4 vCPU, 8GB), Large (8 vCPU, 16GB), or X-Large (16 vCPU, 32GB).                                                      |

              **Step 2: Interface Configuration**

              | CoPilot Parameter Name | Description                                                                                                                        |
              | ---------------------- | ---------------------------------------------------------------------------------------------------------------------------------- |
              | **WAN**                | Interface, IP assignment, Interface labels, Interface CIDR, Default gateway IP, Public IP                                          |
              | **LAN**                | Interface, IP assignment, VRRP, Support for IPv6, Interface CIDR, IPv6 CIDR, VRRP gateway IP, Default gateway IP, Interface labels |
              | **+ VLAN Interface**   | VLAN ID, VLAN interface CIDR, Default gateway IP, Sub-interface tag                                                                |
              | **MGMT**               | Interface, IP assignment, Private network, Egress CIDR (primary), Egress CIDR (secondary)                                          |

              **Step 3: Interface Mapping (View only)**

              | CoPilot Parameter Name               | Description                                                             |
              | ------------------------------------ | ----------------------------------------------------------------------- |
              | Interface                            | Shows the logical interface name of the Edge Gateway.                   |
              | Primary Gateway Ethernet Interface   | Shows the Linux interface name of the primary Edge Gateway.             |
              | Secondary Gateway Ethernet Interface | Shows the Linux interface name of the secondary Edge Gateway (HA only). |
            </Accordion>

            <Accordion title="Create Edge Spoke Gateway (Equinix)">
              To create an Edge Spoke Gateway on Equinix Network Edge:

              1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Edge Gateways** > **Spoke Gateways**.<br />A table appears with the list of Edge Spoke Gateways.
              2. Click **+ Spoke Gateway**.<br />The Create Edge Spoke Gateway wizard appears.
              3. In **Step 1: Gateway Configuration**, provide Name, Platform, Site, ZTP file type (cloud-init), and High availability (Off for primary). Refer to the Equinix Parameter Details table.
              4. Click **Next**.
              5. In **Step 2: Interface Configuration**, click **+ WAN Interface** and configure the WAN interface. Optionally, turn **BGP** On and provide BGP parameters for CSP underlay.
              6. Configure the LAN interface and MGMT interface.
              7. Click **Create** or **Save**.

              A notification appears when the Edge Spoke Gateway is created. You can enable High availability after the primary is created.

              ### Parameter Details

              **Step 1: Gateway Configuration**

              | CoPilot Parameter Name | Description                                                                                                  |
              | ---------------------- | ------------------------------------------------------------------------------------------------------------ |
              | Name                   | Enter a name for the Edge Gateway. The name starts with a letter and uses letters, numbers, and dashes only. |
              | Platform               | Select the platform account. Create or edit from **Cloud Fabric** > **Hybrid Cloud** > **Platforms**.        |
              | Site                   | Select or enter a name that identifies the edge location.                                                    |
              | ZTP file type          | Set to **cloud-init**.                                                                                       |
              | High availability      | Set to **Off** for the primary. Turn **On** after the primary is created.                                    |

              **Step 2: Interface Configuration**

              | CoPilot Parameter Name | Description                                                                                                                                                                  |
              | ---------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
              | **WAN**                | Interface, Interface labels, BGP, Interface primary CIDR, Default gateway IP, Public IP. BGP on: Link-local underlay CIDR, Remote ASN, Local LAN IP, Remote LAN IP, Password |
              | **LAN**                | Interface, Interface CIDR, IPv6 CIDR, Default gateway IP, Default gateway IPv6                                                                                               |
              | **MGMT**               | IP Assignment, Private network, Interface CIDR, Default Gateway IP, Primary DNS, Secondary DNS, Egress CIDR (primary)                                                        |
            </Accordion>

            <Accordion title="Create Edge Spoke Gateway (Self managed)">
              To create an Edge Spoke Gateway on a Self managed platform (VMware ESXi or KVM):

              1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Edge Gateways** > **Spoke Gateways**.<br />A table appears with the list of Edge Spoke Gateways.
              2. Click **+ Spoke Gateway**.<br />The Create Edge Spoke Gateway wizard appears.
              3. In **Step 1: Gateway Configuration**, provide Name, Platform (edge\_admin), Site, ZTP file type (iso for VMware ESXi; iso or cloud-init for KVM), and High availability. Refer to the Self managed Parameter Details table.
              4. Click **Next**.
              5. In **Step 2: Interface Configuration**, configure the WAN, LAN (with optional VLAN interfaces), and MGMT interfaces.
              6. Click **Create** or **Save**.

              A notification appears when the Edge Spoke Gateway is created.

              ### Parameter Details

              **Step 1: Gateway Configuration**

              | CoPilot Parameter Name | Description                                                                         |
              | ---------------------- | ----------------------------------------------------------------------------------- |
              | Name                   | Enter a name for the Edge Gateway.                                                  |
              | Platform               | Select **edge\_admin**.                                                             |
              | Site                   | Select or enter a name that identifies the edge location.                           |
              | ZTP file type          | For VMware ESXi select **iso**. For KVM select **iso** or **cloud-init**.           |
              | High availability      | **Off** for primary. For secondary, select **Active-Active** or **Active-Standby**. |

              **Step 2: Interface Configuration**

              | CoPilot Parameter Name | Description                                                                                                                                                                      |
              | ---------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
              | **WAN**                | IP assignment, Interface labels, Interface CIDR, Default gateway IP, Public IP                                                                                                   |
              | **LAN**                | IP assignment, VRRP, Interface CIDR, VRRP gateway IP, Default gateway IP, Interface labels                                                                                       |
              | **VLAN**               | Interface CIDR, VRRP gateway IP, Default gateway IP, Interface labels. VLAN sub-interfaces: VLAN ID, VLAN interface CIDR, VRRP gateway IP, Default gateway IP, Sub-interface tag |
              | **MGMT**               | IP assignment, Private network, Egress CIDR                                                                                                                                      |
            </Accordion>

            <Accordion title="Create Edge Spoke Gateway (Megaport)">
              To create an Edge Spoke Gateway on Megaport:

              1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Edge Gateways** > **Spoke Gateways**.<br />A table appears with the list of Edge Spoke Gateways.
              2. Click **+ Spoke Gateway**.<br />The Create Edge Spoke Gateway wizard appears.
              3. In **Step 1: Gateway Configuration**, provide Name, Platform, Site, ZTP file type (cloud-init), and High availability (Off for primary). Refer to the Parameter Details table below.
              4. Click **Next**.
              5. In **Step 2: Interface Configuration**, configure the WAN interface (with optional BGP for CSP underlay), LAN interface, and MGMT interface.
              6. Click **Create** or **Save**.

              A notification appears when the Edge Spoke Gateway is created. You can enable High availability after the primary is created.

              ### Parameter Details

              **Step 1: Gateway Configuration**

              | CoPilot Parameter Name | Description                                                                                                  |
              | ---------------------- | ------------------------------------------------------------------------------------------------------------ |
              | Name                   | Enter a name for the Edge Gateway. The name starts with a letter and uses letters, numbers, and dashes only. |
              | Platform               | Select the platform account. Create or edit from **Cloud Fabric** > **Hybrid Cloud** > **Platforms**.        |
              | Site                   | Select or enter a name that identifies the edge location.                                                    |
              | ZTP file type          | Set to **cloud-init**.                                                                                       |
              | High availability      | Set to **Off** for the primary. Turn **On** after the primary is created.                                    |

              **Step 2: Interface Configuration**

              | CoPilot Parameter Name | Description                                                                                                                                                                  |
              | ---------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
              | **WAN**                | Interface, Interface labels, BGP, Interface primary CIDR, Default gateway IP, Public IP. BGP on: Link-local underlay CIDR, Remote ASN, Local LAN IP, Remote LAN IP, Password |
              | **LAN**                | Interface, Interface labels, Interface CIDR, Default gateway IP                                                                                                              |
              | **MGMT**               | Interface, IP assignment, Private network                                                                                                                                    |
            </Accordion>

            <Accordion title="Edit Edge Spoke Gateway">
              To edit an Edge Spoke Gateway:

              1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Edge Gateways** > **Spoke Gateways**.<br />A table appears with the list of Edge Spoke Gateways.
              2. Locate the Edge Spoke Gateway and click the **Edit** icon on the row.<br />The **Edit Spoke Gateway** dialog appears.
              3. Make the configuration changes needed.
              4. Click **Done**.

              A notification appears confirming the changes to the Edge Spoke Gateway.

              ### Parameter Details

              | CoPilot Parameter Name  | Description                                                                                  |
              | ----------------------- | -------------------------------------------------------------------------------------------- |
              | Site                    | Change the edge location identifier.                                                         |
              | High availability       | Enable or change HA mode (Active-Standby or Active-Active) after the primary is created.     |
              | Interface Configuration | Modify WAN, LAN, and Management interface settings (CIDR, default gateway, VRRP, Public IP). |
              | + Instance              | Add HA instances; configure subnet and Public IP for new instances.                          |
              | Jumbo Frame             | Enable or disable Jumbo Frame for improved throughput.                                       |
            </Accordion>

            <Accordion title="Delete Edge Spoke Gateway">
              To delete an Edge Spoke Gateway:

              1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Edge Gateways** > **Spoke Gateways**.<br />A table appears with the list of Edge Spoke Gateways.
              2. Locate the Edge Spoke Gateway and click the **Delete** icon on the row.<br />The delete confirmation dialog appears.
              3. Read the warning message and confirm the deletion.

              The Edge Spoke Gateway is deleted along with its attachments. A notification appears confirming the deletion.
            </Accordion>
          </Accordion>

          <Accordion title="Manage Gateway Attachments">
            To manage Edge Spoke Gateway attachments to Transit Gateways or Edge Transit Gateways:

            1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Edge Gateways** > **Spoke Gateways**.<br />A table appears with the list of Edge Spoke Gateways.
            2. Locate the Edge Spoke Gateway and click the **Manage Gateway Attachments** icon on the row.<br />The **Manage Gateway Attachments** panel appears.
            3. In the **Transit Gateway** or **Edge Transit Gateway** tab, click **+ Attachment** to add an attachment, or remove attachments as needed.
            4. Provide the attachment details. Refer to the Parameter Details table.
            5. Click **Save**.

            The Edge Spoke Gateway is attached to the selected Transit Gateway or Edge Transit Gateway for encrypted connectivity.

            ### Parameter Details

            | CoPilot Parameter Name           | Description                                                                                                                                 |
            | -------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------- |
            | Transit Gateway                  | Select the Transit Gateway in cloud or Edge Transit Gateway to attach.                                                                      |
            | Local Edge Gateway Interface     | Select the WAN interface of the local Edge Spoke Gateway to use for the attachment.                                                         |
            | Attach Over                      | Select **Private Network** or **Public Network** for the connection.                                                                        |
            | ActiveMesh                       | Turn **On** for full mesh peering between local and remote Edge Gateways.                                                                   |
            | Jumbo Frame                      | Turn **On** to improve performance for the connection. Applicable for Private network attachments.                                          |
            | Number of HPE Tunnels            | **Single**: One tunnel. **Maximum**: Maximum tunnels based on gateway sizes. **Custom**: Specify the number. Available for Private network. |
            | Customize Route Table Attachment | Turn **On** to select route tables to attach to the Spoke Gateway.                                                                          |
          </Accordion>

          <Accordion title="Actions on Edge Spoke Gateway">
            <Accordion title="Manage NAT mappings on the Gateway interface">
              To manage NAT mappings on the Gateway interface:

              1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Edge Gateways** > **Spoke Gateways**.<br />A table appears with the list of Edge Spoke Gateways.
              2. Locate the Edge Spoke Gateway and open the **Actions** menu on the row.
              3. Select **Manage NAT mappings on the Gateway interface**.<br />The NAT mappings panel appears.
              4. Add, edit, or remove NAT mappings as needed.
              5. Click **Done**.

              The NAT mappings are updated for the Edge Spoke Gateway.
            </Accordion>
          </Accordion>

          <Accordion title="Gateway-Specific Actions">
            <Accordion title="Configure SNAT on an Edge Spoke Gateway">
              When SNAT is enabled, traffic from connected networks can use the Edge Spoke Gateway for source address translation, depending on rule and **Apply Route Entry** settings. You can use a **Single IP** or a range of addresses through **Customized SNAT** rules.

              <Note>**Note:** NAT rules do not copy from the primary gateway to high availability (HA) instances. Configure SNAT rules separately for each instance you select in the **Instance** dropdown.</Note>

              <Note>**Note:** Each gateway allows up to 2000 SNAT rules. To edit multiple translated source IPs in one rule, use Aviatrix Controller; CoPilot does not support that edit path.</Note>

              To enable SNAT and add rules:

              1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Edge Gateways** > **Spoke Gateways**.<br />A table appears with the list of Edge Spoke Gateways.
              2. Click the Edge Spoke Gateway name.<br />The Edge Spoke Gateway Details page opens.
              3. Click the **Settings** tab. Expand **Network Address Translation (NAT)**.
              4. Turn **Source NAT** to **On**.
              5. Choose **Single IP** (default: Edge Spoke Gateway primary IP as the SNAT address) or **Customized SNAT** (rules-based translation).
              6. In **Instance**, select the primary gateway or an HA instance to configure.
              7. For **Customized SNAT**, click **+ Rule**, enter fields from the **Parameter Details**.
              8. Click **Save**.

              The SNAT rules are added to the Edge Spoke Gateway.

              ### Parameter Details

              | CoPilot Parameter Name | Description                                                                                                                                                                                                        |
              | ---------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
              | Source CIDR            | Source IP range for the rule.<br />Leave blank if unused.                                                                                                                                                          |
              | Source Port            | Source port for the rule.<br />Leave blank if unused.                                                                                                                                                              |
              | Destination CIDR       | Destination IP range.<br />If blank, a default route 0.0.0.0/0 to the gateway can be programmed in the cloud route table where applicable.                                                                         |
              | Destination Port       | Destination port.<br />Leave blank if unused.                                                                                                                                                                      |
              | Protocol               | Protocol for the destination port.<br />Leave blank if unused.                                                                                                                                                     |
              | Connection             | Output connection for the rule.<br />Leave blank if unused.                                                                                                                                                        |
              | Mark                   | TCP session mark or tag.<br />Leave blank if unused.                                                                                                                                                               |
              | SNAT IPs               | Translated source IP when conditions match.<br />Supports a range (for example, 100.100.1.5–100.100.1.10).<br />At least one of **SNAT IPs** or **SNAT Port** must be set for the rule to take effect, per the UI. |
              | SNAT Port              | Translated source port when conditions match.<br />At least one of **SNAT IPs** or **SNAT Port** must be set for the rule to take effect, per the UI.                                                              |
              | Apply Route Entry      | When enabled, programs a cloud route so **Destination CIDR** points to the Aviatrix Gateway.                                                                                                                       |
              | Exclude Route Table    | Private route tables to exclude from default route programming when combined with **Apply Route Entry**.                                                                                                           |
            </Accordion>

            <Accordion title="Configure DNAT on an Edge Spoke Gateway">
              Destination NAT (DNAT) rules translate the destination IP address of packets the Edge Spoke Gateway **receives from other networks** to a virtual address range. **Apply Route Entry** and **Exclude Route Table** control optional cloud route programming related to **Destination CIDR**, as in the Parameter Details table.

              <Note>**Note:** NAT rules do not copy from the primary gateway to high availability (HA) instances. Configure DNAT rules separately for each instance you select in the **Instance** dropdown.</Note>

              <Note>**Note:** Each gateway allows up to 2000 DNAT rules. To edit multiple translated destination IP addresses in one rule, use Aviatrix Controller; CoPilot does not support that edit path.</Note>

              To enable DNAT and add rules:

              1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Edge Gateways** > **Spoke Gateways**.<br />A table appears with the list of Edge Spoke Gateways.
              2. Click the Edge Spoke Gateway name.<br />The Edge Spoke Gateway Details page opens.
              3. Click the **Settings** tab. Expand **Network Address Translation (NAT)**.
              4. Turn **Destination NAT** to **On**.
              5. In **Instance**, select the primary gateway or an HA instance to configure.
              6. Click **+ Rule**. Enter fields from the **Parameter Details** table.
              7. Click **Save**.

              The DNAT rules are added to the Edge Spoke Gateway.

              ### Parameter Details

              | CoPilot Parameter Name | Description                                                                                                                                                                                                             |
              | ---------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
              | Source CIDR            | Source IP range for the rule.<br />Leave blank if unused.                                                                                                                                                               |
              | Source Port            | Source port for the rule.<br />Leave blank if unused.                                                                                                                                                                   |
              | Destination CIDR       | Destination IP range before translation.<br />If blank, default route 0.0.0.0/0 behavior can apply as in the UI.                                                                                                        |
              | Destination Port       | Destination port.<br />Leave blank if unused.                                                                                                                                                                           |
              | Protocol               | Protocol for the destination port.<br />Leave blank if unused.                                                                                                                                                          |
              | Connection             | Output connection for the rule.<br />Leave blank if unused.                                                                                                                                                             |
              | Mark                   | TCP session mark or tag.<br />Leave blank if unused.                                                                                                                                                                    |
              | DNAT IPs               | Translated destination IP when conditions match.<br />Supports a range (for example, 100.101.2.5–100.101.2.10).<br />At least one of **DNAT IPs** or **DNAT Port** must be set for the rule to take effect, per the UI. |
              | DNAT Port              | Translated destination port when conditions match.<br />At least one of **DNAT IPs** or **DNAT Port** must be set for the rule to take effect, per the UI.                                                              |
              | Apply Route Entry      | When enabled, programs a cloud route so **Destination CIDR** points to the Aviatrix Gateway.                                                                                                                            |
              | Exclude Route Table    | Private route tables to exclude from default route programming when combined with **Apply Route Entry**.                                                                                                                |
            </Accordion>

            <Accordion title="Configure Manual BGP Advertised CIDR List">
              Use a manual advertised CIDR list to control what this BGP-enabled Edge Spoke Gateway sends to neighbors.

              **Gateway mode** sets one advertised CIDR list for all BGP peerings on the gateway. **Connection mode** sets the list per remote BGP peer.

              <Note>**Local ASN:** Set the gateway ASN in **BGP** before peering. AS numbers are unique 2-byte (for example, 64512-65534) or 4-byte values.</Note>

              To configure manual BGP route advertisement:

              1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Edge Gateways** > **Spoke Gateways**.<br />A table appears with the list of Edge Spoke Gateways.
              2. Click the Edge Spoke Gateway name.<br />The Edge Spoke Gateway Details page opens.
              3. Click the **Settings** tab. Expand **Border Gateway Protocol (BGP)**.
              4. Scroll to **Manual BGP Advertised CIDR List**.
                 * For all BGP connections: enter CIDRs in **Advertised CIDRs (Per Gateway)**.
                 * For one connection: select the connection in **Connection**, then enter CIDRs in **Advertised CIDRs (Per Connection)**.
              5. Click **Save**.
            </Accordion>

            <Accordion title="Configure BGP AS Path Prepend">
              Prepend AS numbers on the **AS\_PATH** the gateway advertises to peers. If unset, only the gateway ASN is advertised.

              **Gateway mode** prepends for all BGP peerings. **Connection mode** prepends for one selected peer.

              To configure AS Path Prepend:

              1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Edge Gateways** > **Spoke Gateways**.<br />A table appears with the list of Edge Spoke Gateways.
              2. Click the Edge Spoke Gateway name.<br />The Edge Spoke Gateway Details page opens.
              3. Click the **Settings** tab. Expand **Border Gateway Protocol (BGP)**.
              4. Scroll to **AS Path Prepend**.
                 * For all BGP connections: enter values in **Prepend AS Path (Per Gateway)**.
                 * For one connection: select the connection in **Connection**, then enter values in **Prepend AS Path (Per Connection)**.
              5. Click **Save**.
            </Accordion>

            <Accordion title="Configure Preserve AS Path (BGP)">
              Applies when **Manual BGP Advertised CIDR List** is set.

              * **On:** AS Path is preserved; manual advertised CIDRs are not advertised if they are no longer in the best route DB.
              * **Off:** AS Path is stripped on advertisements to neighbors.

              To set Preserve AS Path:

              1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Edge Gateways** > **Spoke Gateways**.<br />A table appears with the list of Edge Spoke Gateways.
              2. Click the Edge Spoke Gateway name.<br />The Edge Spoke Gateway Details page opens.
              3. Click the **Settings** tab. Expand **Border Gateway Protocol (BGP)**.
              4. Set **Preserve AS Path** as needed.
              5. Click **Save**.
            </Accordion>

            <Accordion title="Configure BGP ECMP">
              With multiple BGP connections, the Controller normally picks one best route. **BGP ECMP** can merge equal routes and load-share traffic by ECMP hashing.

              To enable BGP ECMP:

              1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Edge Gateways** > **Spoke Gateways**.<br />A table appears with the list of Edge Spoke Gateways.
              2. Click the Edge Spoke Gateway name.<br />The Edge Spoke Gateway Details page opens.
              3. Click the **Settings** tab. Expand **Border Gateway Protocol (BGP)**.
              4. Turn **BGP ECMP** **On**.
              5. Click **Save**.
            </Accordion>

            <Accordion title="Configure BGP Polling Time">
              BGP routes are reported to the Controller on a timer (default 50 seconds). Shorter values can speed convergence.

              To change BGP polling time:

              1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Edge Gateways** > **Spoke Gateways**.<br />A table appears with the list of Edge Spoke Gateways.
              2. Click the Edge Spoke Gateway name.<br />The Edge Spoke Gateway Details page opens.
              3. Click the **Settings** tab. Expand **Border Gateway Protocol (BGP)**.
              4. Set **BGP Polling Time** between **10** and **50** seconds.
              5. Click **Save**.
            </Accordion>

            <Accordion title="Configure BGP Hold Time">
              **Hold time** is how long the gateway waits for BGP messages before treating the neighbor as down.

              To set BGP hold time:

              1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Edge Gateways** > **Spoke Gateways**.<br />A table appears with the list of Edge Spoke Gateways.
              2. Click the Edge Spoke Gateway name.<br />The Edge Spoke Gateway Details page opens.
              3. Click the **Settings** tab. Expand **Border Gateway Protocol (BGP)**.
              4. Set **BGP Hold Time** between **12** and **180** seconds.
              5. Click **Save**.
            </Accordion>

            <Accordion title="Enable Gateway Learned CIDR Approval">
              With **Gateway Learned CIDR Approval** **On**, the Controller emails the administrator to approve learned CIDRs before propagation.

              Approval applies to all BGP connections on this Edge Spoke Gateway (**Gateway** mode only).

              To enable Gateway Learned CIDR Approval:

              1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Edge Gateways** > **Spoke Gateways**.<br />A table appears with the list of Edge Spoke Gateways.
              2. Click the Edge Spoke Gateway name.<br />The Edge Spoke Gateway Details page opens.
              3. Click the **Settings** tab. Expand **Border Gateway Protocol (BGP)**.
              4. Turn **Gateway Learned CIDR Approval** **On**.
              5. Click **Save**.
            </Accordion>
          </Accordion>
        </AccordionGroup>
      </Tab>

      <Tab title="Transit Gateways">
        ## Purpose

        The **Transit Gateways** page shows a table of Edge Transit Gateways deployed for hybrid connectivity and their configurations and statuses.

        ## Elements

        <Frame>
          <img src={"/images/reference/ui/cloud-fabric/hybrid-edge-transit.png"} alt="Hybrid Cloud: Edge Transit Gateways" width="100%" />
        </Frame>

        * **+ Transit Gateway button**: Starts workflow to deploy a new Edge Transit Gateway.
        * **Edge Transit Gateway table**: Displays Edge Transit Gateway name, Platform type, Site, Device, Private IP, Transit Gateway, and Status.
        * **Edit button**: Opens configuration panel to modify Edge Transit Gateway settings.
        * **Manage Gateway Attachments button**: Opens a panel to manage the Edge Transit Gateway attachments.
        * **Delete button**: Deletes the selected Edge Transit Gateway.
        * **Actions menu**: Manage NAT mappings on the Gateway interface.

        **Create Transit Gateway wizard**

        * **Step 1: Gateway Configuration**: Name, Platform, Site, High availability, Device(s), Gateway Resource Size, ZTP file type.
        * **Step 2: Interface Configuration**: WAN and MGMT interfaces. See Create Edge Transit Gateway accordions for platform-specific steps.
        * **Step 3: Interface Mapping**: Logical-to-physical interface mapping (view only).

        <Frame>
          <img src={"/images/reference/ui/cloud-fabric/hybrid-edge-transit-create-1.png"} alt="Hybrid Cloud: Create Edge Transit Gateway - Step 1" width="100%" />
        </Frame>

        <Frame>
          <img src={"/images/reference/ui/cloud-fabric/hybrid-edge-transit-create-2.png"} alt="Hybrid Cloud: Create Edge Transit Gateway - Step 2" width="100%" />
        </Frame>

        <Frame>
          <img src={"/images/reference/ui/cloud-fabric/hybrid-edge-transit-create-3.png"} alt="Hybrid Cloud: Create Edge Transit Gateway - Step 3" width="100%" />
        </Frame>

        ## Actions

        <AccordionGroup>
          <Accordion title="Configure Edge Transit Gateway">
            <Accordion title="View Edge Transit Gateways">
              To view the list of Edge Transit Gateways and their details:

              1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Edge Gateways** > **Transit Gateways**.<br />The Transit Gateways page appears with a table of Edge Transit Gateways.
              2. Click an Edge Transit Gateway name to view its details.

              The table displays the list of Edge Transit Gateways with their configurations and status.

              ### Parameter Details

              | CoPilot Parameter Name      | Description                                                                                    |
              | --------------------------- | ---------------------------------------------------------------------------------------------- |
              | Name                        | The name assigned to the Transit Gateway.                                                      |
              | Platform Type               | Type of platform (AEP, Equinix, Self managed, Megaport) where the Transit Gateway is deployed. |
              | Site                        | Site where the Transit Gateway is deployed.                                                    |
              | Device                      | Device associated with the Transit Gateway.                                                    |
              | Private IP                  | Private IP address of the Transit Gateway.                                                     |
              | Transit Gateway Attachments | Number of Transit Gateways attached to the Transit Gateway.                                    |
              | Spoke Gateway Attachments   | Number of Spoke Gateways attached to the Transit Gateway.                                      |
              | Status                      | Current status of the Transit Gateway.                                                         |
            </Accordion>

            <Accordion title="Create Edge Transit Gateway (AEP)">
              To create an Edge Transit Gateway on the Aviatrix Edge Platform:

              1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Edge Gateways** > **Transit Gateways**.<br />A table appears with the list of Edge Transit Gateways.
              2. Click **+ Transit Gateway**.<br />The Create Transit Gateway wizard appears.
              3. In **Step 1: Gateway Configuration**, provide Name, Platform, Site, High availability, Primary Device, Secondary Device (if HA), and Gateway Resource Size. Refer to the Parameter Details table below.
              4. Click **Next**.
              5. In **Step 2: Interface Configuration**, click **WAN** and configure the WAN interface. Optionally, turn **BGP** On for CSP underlay. Click **MGMT** and configure the Management interface.
              6. In **Step 3: Interface Mapping**, review the logical-to-physical interface mapping.
              7. Click **Create** or **Save**.

              A notification appears when the Edge Transit Gateway is created.

              ### Parameter Details

              **Step 1: Gateway Configuration**

              | CoPilot Parameter Name | Description                                                                                                             |
              | ---------------------- | ----------------------------------------------------------------------------------------------------------------------- |
              | Name                   | Enter a name for the Edge Transit Gateway. The name must start with a letter and use only letters, numbers, and dashes. |
              | Platform               | Select the platform account. Create or edit from **Cloud Fabric** > **Hybrid Cloud** > **Platforms**.                   |
              | Site                   | Enter or select a name that identifies the edge location.                                                               |
              | High availability      | **Off** for primary only. **On (Active-Active)** for load sharing across peerings.                                      |
              | Primary Device         | Select the edge device for the primary Edge Transit Gateway.                                                            |
              | Secondary Device       | Select the edge device for the secondary (HA) Edge Transit Gateway.                                                     |
              | Gateway Resource Size  | Small (2 vCPU, 4GB), Medium (4 vCPU, 8GB), Large (8 vCPU, 16GB), or X-Large (16 vCPU, 32GB).                            |

              **Step 2: Interface Configuration**

              | CoPilot Parameter Name | Description                                                                                                                                                                                                                       |
              | ---------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
              | **WAN**                | Interface, IP assignment, Interface labels, BGP, Interface primary CIDR, Interface secondary CIDRs, Default gateway IP, Public IP. BGP on: Link-local underlay CIDR, Local ASN, Remote ASN, Local LAN IP, Remote LAN IP, Password |
              | **MGMT**               | Interface, IP assignment, Private network, Egress CIDR (primary), Egress CIDR (secondary)                                                                                                                                         |

              **Step 3: Interface Mapping (View only)**

              | CoPilot Parameter Name               | Description                                                                     |
              | ------------------------------------ | ------------------------------------------------------------------------------- |
              | Interface                            | Shows the logical interface name of the Edge Transit Gateway.                   |
              | Primary Gateway Ethernet Interface   | Shows the Linux interface name of the primary Edge Transit Gateway.             |
              | Secondary Gateway Ethernet Interface | Shows the Linux interface name of the secondary Edge Transit Gateway (HA only). |
            </Accordion>

            <Accordion title="Create Edge Transit Gateway (Equinix)">
              To create an Edge Transit Gateway on Equinix Network Edge:

              1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Edge Gateways** > **Transit Gateways**.<br />A table appears with the list of Edge Transit Gateways.
              2. Click **+ Transit Gateway**.<br />The Create Transit Gateway wizard appears.
              3. In **Step 1: Gateway Configuration**, provide Name, Platform, Site, ZTP file type (cloud-init), and High availability (Off for primary). Refer to the Parameter Details table below.
              4. Click **Next**.
              5. In **Step 2: Interface Configuration**, click **+ WAN Interface** and configure the WAN interface. Optionally, turn **BGP** On for CSP underlay. Click **MGMT** and configure the Management interface.
              6. In **Step 3: Interface Mapping**, review the logical-to-physical interface mapping.
              7. Click **Create** or **Save**.

              A notification appears when the Edge Transit Gateway is created. You can enable High availability after the primary is created.

              ### Parameter Details

              **Step 1: Gateway Configuration**

              | CoPilot Parameter Name | Description                                                                                                             |
              | ---------------------- | ----------------------------------------------------------------------------------------------------------------------- |
              | Name                   | Enter a name for the Edge Transit Gateway. The name must start with a letter and use only letters, numbers, and dashes. |
              | Platform               | Select the platform account. Create or edit from **Cloud Fabric** > **Hybrid Cloud** > **Platforms**.                   |
              | Site                   | Enter or select a name that identifies the edge location.                                                               |
              | ZTP file type          | Set to **cloud-init**.                                                                                                  |
              | High availability      | Set to **Off** for the primary. Turn **On** after the primary is created.                                               |

              **Step 2: Interface Configuration**

              | CoPilot Parameter Name | Description                                                                                                                                                                                                                                                         |
              | ---------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
              | **WAN**                | Interface, Interface labels, BGP, IPv6, Interface primary CIDR, Interface secondary CIDRs, Interface IPv6 CIDR, Default Gateway IPv6, Default gateway IP, Public IP. BGP on: Link-local underlay CIDR, Local ASN, Remote ASN, Local LAN IP, Remote LAN IP, Password |
              | **MGMT**               | Interface, IP assignment, Private network, Egress CIDR (primary)                                                                                                                                                                                                    |
            </Accordion>

            <Accordion title="Create Edge Transit Gateway (Self managed)">
              To create an Edge Transit Gateway on a Self managed platform (VMware ESXi or KVM):

              1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Edge Gateways** > **Transit Gateways**.<br />A table appears with the list of Edge Transit Gateways.
              2. Click **+ Transit Gateway**.<br />The Create Transit Gateway wizard appears.
              3. In **Step 1: Gateway Configuration**, provide Name, Platform (edge\_admin), Site, ZTP file type (iso for VMware ESXi; cloud-init for KVM), and High availability. Refer to the Parameter Details table below.
              4. Click **Next**.
              5. In **Step 2: Interface Configuration**, configure the WAN and MGMT interfaces.
              6. In **Step 3: Interface Mapping**, review the logical-to-physical interface mapping.
              7. Click **Create** or **Save**.

              A notification appears when the Edge Transit Gateway is created.

              ### Parameter Details

              **Step 1: Gateway Configuration**

              | CoPilot Parameter Name | Description                                                    |
              | ---------------------- | -------------------------------------------------------------- |
              | Name                   | Enter a name for the Edge Transit Gateway.                     |
              | Platform               | Select **edge\_admin**.                                        |
              | Site                   | Enter or select a name that identifies the edge location.      |
              | ZTP file type          | For VMware ESXi select **iso**. For KVM select **cloud-init**. |
              | High availability      | **Off** for primary. **On (Active-Active)** for load sharing.  |

              **Step 2: Interface Configuration**

              | CoPilot Parameter Name | Description                                                                                            |
              | ---------------------- | ------------------------------------------------------------------------------------------------------ |
              | **WAN**                | Interface, IP assignment, Interface labels, BGP, Interface primary CIDR, Default gateway IP, Public IP |
              | **MGMT**               | IP assignment, Private network, Egress CIDR                                                            |
            </Accordion>

            <Accordion title="Create Edge Transit Gateway (Megaport)">
              To create an Edge Transit Gateway on Megaport:

              1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Edge Gateways** > **Transit Gateways**.<br />A table appears with the list of Edge Transit Gateways.
              2. Click **+ Transit Gateway**.<br />The Create Transit Gateway wizard appears.
              3. In **Step 1: Gateway Configuration**, provide Name, Platform, Site, ZTP file type (cloud-init), and High availability (Off for primary). Refer to the Parameter Details table below.
              4. Click **Next**.
              5. In **Step 2: Interface Configuration**, click **WAN** and configure the WAN interface. Optionally, turn **BGP** On for CSP underlay. Click **MGMT** and configure the Management interface.
              6. In **Step 3: Interface Mapping**, review the logical-to-physical interface mapping.
              7. Click **Create** or **Save**.

              A notification appears when the Edge Transit Gateway is created. You can enable High availability after the primary is created.

              ### Parameter Details

              **Step 1: Gateway Configuration**

              | CoPilot Parameter Name | Description                                                                                                             |
              | ---------------------- | ----------------------------------------------------------------------------------------------------------------------- |
              | Name                   | Enter a name for the Edge Transit Gateway. The name must start with a letter and use only letters, numbers, and dashes. |
              | Platform               | Select the platform account. Create or edit from **Cloud Fabric** > **Hybrid Cloud** > **Platforms**.                   |
              | Site                   | Enter or select a name that identifies the edge location.                                                               |
              | ZTP file type          | Set to **cloud-init**.                                                                                                  |
              | High availability      | Set to **Off** for the primary. Turn **On** after the primary is created.                                               |

              **Step 2: Interface Configuration**

              | CoPilot Parameter Name | Description                                                                                                                                                                                                        |
              | ---------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
              | **WAN**                | Interface, Interface labels, BGP, Interface primary CIDR, Interface secondary CIDRs, Default gateway IP, Public IP. BGP on: Link-local underlay CIDR, Local ASN, Remote ASN, Local LAN IP, Remote LAN IP, Password |
              | **MGMT**               | Interface, IP assignment, Private network, Egress CIDR (primary)                                                                                                                                                   |
            </Accordion>

            <Accordion title="Edit Edge Transit Gateway">
              To edit an Edge Transit Gateway:

              1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Edge Gateways** > **Transit Gateways**.<br />A table appears with the list of Edge Transit Gateways.
              2. Locate the Edge Transit Gateway and click the **Edit** icon on the row.<br />The Edit Transit Gateway dialog appears.
              3. Make the configuration changes needed.
              4. Click **Done**.

              A notification appears confirming the changes to the Edge Transit Gateway.
            </Accordion>

            <Accordion title="Delete Edge Transit Gateway">
              To delete an Edge Transit Gateway:

              1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Edge Gateways** > **Transit Gateways**.<br />A table appears with the list of Edge Transit Gateways.
              2. Locate the Edge Transit Gateway and click the **Delete** icon on the row.
              3. Confirm the deletion in the dialog.

              A notification appears when the Edge Transit Gateway is deleted.
            </Accordion>
          </Accordion>

          <Accordion title="Manage Gateway Attachments">
            To manage Edge Transit Gateway attachments:

            1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Edge Gateways** > **Transit Gateways**.<br />A table appears with the list of Edge Transit Gateways.
            2. Locate the Edge Transit Gateway and click **Manage Gateway Attachments**.<br />The Manage Gateway Attachments panel appears.
            3. Add, edit, or remove Transit Gateway and Spoke Gateway attachments as needed.
            4. Click **Done**.

            The attachments are updated for the Edge Transit Gateway.
          </Accordion>

          <Accordion title="Actions on Edge Transit Gateway">
            <Accordion title="Manage NAT mappings">
              To manage NAT mappings on the Gateway interface:

              1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Edge Gateways** > **Transit Gateways**.<br />A table appears with the list of Edge Transit Gateways.
              2. Locate the Edge Transit Gateway and open the **Actions** menu on the row.
              3. Select **Manage NAT mappings on the Gateway interface**.<br />The NAT mappings panel appears.
              4. Add, edit, or remove NAT mappings as needed.
              5. Click **Done**.

              The NAT mappings are updated for the Edge Transit Gateway.
            </Accordion>
          </Accordion>

          <Accordion title="Gateway-Specific Actions">
            <Accordion title="Configure SNAT on an Edge Transit Gateway">
              <Note>**Note:** Edge Transit Gateways support NAT only when High Performance Encryption (HPE) is disabled.</Note>

              When SNAT is enabled, private subnet route tables in attached VPCs or VNets can receive a default route (0.0.0.0/0) through the gateway so instances reach the internet, depending on rule and **Apply Route Entry** settings.

              <Note>**Note:** NAT rules do not copy from the primary gateway to high availability (HA) instances. Configure SNAT rules separately for each instance you select in the **Instance** dropdown.</Note>

              <Note>**Note:** Each gateway allows up to 2000 SNAT rules and up to 2000 DNAT rules. To edit multiple translated IPs in one rule, use Aviatrix Controller; CoPilot does not support that edit path.</Note>

              To enable SNAT and add rules:

              1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Edge Gateways** > **Transit Gateways**.<br />A table appears with the list of Edge Transit Gateways.
              2. Click the Edge Transit Gateway name.<br />The Edge Transit Gateway Details page opens.
              3. Click the **Settings** tab. Expand **Network Address Translation (NAT)**.
              4. Turn **Source NAT** to **On**.
              5. In **Instance**, select the primary gateway or an HA instance to configure.
              6. Click **+ Rule**. Enter rule fields.<br />Refer to the Parameter Details table for more details.
              7. Click **Save**.

              The SNAT rules are added to the Edge Transit Gateway.

              ### Parameter Details

              | CoPilot Parameter Name | Description                                                                                                                                                                                                        |
              | ---------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
              | Source CIDR            | Source IP range for the rule.<br />Leave blank if unused.                                                                                                                                                          |
              | Source Port            | Source port for the rule.<br />Leave blank if unused.                                                                                                                                                              |
              | Destination CIDR       | Destination IP range.<br />If blank, a default route 0.0.0.0/0 to the gateway can be programmed in the cloud route table.                                                                                          |
              | Destination Port       | Destination port.<br />Leave blank if unused.                                                                                                                                                                      |
              | Protocol               | Protocol for the destination port.<br />Leave blank if unused.                                                                                                                                                     |
              | Connection             | Output connection for the rule.<br />Leave blank if unused.                                                                                                                                                        |
              | Mark                   | TCP session mark or tag.<br />Leave blank if unused.                                                                                                                                                               |
              | SNAT IPs               | Translated source IP when conditions match.<br />Supports a range (for example, 100.100.1.5–100.100.1.10).<br />At least one of **SNAT IPs** or **SNAT Port** must be set for the rule to take effect, per the UI. |
              | SNAT Port              | Translated source port when conditions match.<br />At least one of **SNAT IPs** or **SNAT Port** must be set for the rule to take effect, per the UI.                                                              |
              | Apply Route Entry      | When enabled, programs a cloud route so **Destination CIDR** points to the Edge Transit Gateway.                                                                                                                   |
              | Exclude Route Table    | Private route tables to exclude from default route programming when combined with **Apply Route Entry**.                                                                                                           |
            </Accordion>

            <Accordion title="Configure DNAT on an Edge Transit Gateway">
              Destination NAT (DNAT) rules translate the destination IP address of packets the Edge Transit Gateway receives from other networks to a virtual address range. **Apply Route Entry** and **Exclude Route Table** control optional cloud route programming related to **Destination CIDR**, as in the Parameter Details table.

              <Note>**Note:** NAT rules do not copy from the primary gateway to high availability (HA) instances. Configure DNAT rules separately for each instance you select in the **Instance** dropdown.</Note>

              <Note>**Note:** Each gateway allows up to 2000 DNAT rules. To edit multiple translated IPs in one rule, use Aviatrix Controller; CoPilot does not support that edit path.</Note>

              To enable DNAT and add rules:

              1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Edge Gateways** > **Transit Gateways**.<br />A table appears with the list of Edge Transit Gateways.
              2. Click the Edge Transit Gateway name.<br />The Edge Transit Gateway Details page opens.
              3. Click the **Settings** tab. Expand **Network Address Translation (NAT)**.
              4. Turn **Destination NAT** to **On**.
              5. In **Instance**, select the primary gateway or an HA instance to configure.
              6. Click **+ Rule**. Enter rule fields.<br />Refer to the Parameter Details table for more details.
              7. Click **Save**.

              The DNAT rules are added to the Edge Transit Gateway.

              ### Parameter Details

              | CoPilot Parameter Name | Description                                                                                                                                                                                                             |
              | ---------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
              | Source CIDR            | Source IP range for the rule.<br />Leave blank if unused.                                                                                                                                                               |
              | Source Port            | Source port for the rule.<br />Leave blank if unused.                                                                                                                                                                   |
              | Destination CIDR       | Destination IP range before translation.<br />If blank, default route 0.0.0.0/0 behavior can apply as in the UI.                                                                                                        |
              | Destination Port       | Destination port.<br />Leave blank if unused.                                                                                                                                                                           |
              | Protocol               | Protocol for the destination port.<br />Leave blank if unused.                                                                                                                                                          |
              | Connection             | Output connection for the rule.<br />Leave blank if unused.                                                                                                                                                             |
              | Mark                   | TCP session mark or tag.<br />Leave blank if unused.                                                                                                                                                                    |
              | DNAT IPs               | Translated destination IP when conditions match.<br />Supports a range (for example, 100.101.2.5–100.101.2.10).<br />At least one of **DNAT IPs** or **DNAT Port** must be set for the rule to take effect, per the UI. |
              | DNAT Port              | Translated destination port when conditions match.<br />At least one of **DNAT IPs** or **DNAT Port** must be set for the rule to take effect, per the UI.                                                              |
              | Apply Route Entry      | When enabled, programs a cloud route so **Destination CIDR** points to the Edge Transit Gateway.                                                                                                                        |
              | Exclude Route Table    | Private route tables to exclude from default route programming when combined with **Apply Route Entry**.                                                                                                                |
            </Accordion>

            <Accordion title="Configure Manual BGP Advertised CIDR List">
              By default, an Edge Transit Gateway advertises individual Spoke VPC/VNet CIDRs to BGP neighbors. Use a manual list to limit total routes.

              **Gateway mode** sets one advertised CIDR list for all BGP peerings on the gateway. **Connection mode** sets the list per remote BGP peer.

              <Note>**Local ASN:** Set the gateway ASN in **BGP** before peering. AS numbers are unique 2-byte (for example, 64512-65534) or 4-byte values.</Note>

              To configure manual BGP route advertisement:

              1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Edge Gateways** > **Transit Gateways**.<br />A table appears with the list of Edge Transit Gateways.
              2. Click the Edge Transit Gateway name.<br />The Edge Transit Gateway Details page opens.
              3. Click the **Settings** tab. Expand **Border Gateway Protocol (BGP)**.
              4. Scroll to **Manual BGP Advertised CIDR List**.
                 * For all BGP connections: enter CIDRs in **Advertised CIDRs (Per Gateway)**.
                 * For one connection: select the connection in **Connection**, then enter CIDRs in **Advertised CIDRs (Per Connection)**.
              5. Click **Save**.
            </Accordion>

            <Accordion title="Configure BGP AS Path Prepend">
              Prepend AS numbers on the **AS\_PATH** the gateway advertises to peers. If unset, only the gateway ASN is advertised.

              **Gateway mode** prepends for all BGP peerings. **Connection mode** prepends for one selected peer.

              To configure AS Path Prepend:

              1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Edge Gateways** > **Transit Gateways**.<br />A table appears with the list of Edge Transit Gateways.
              2. Click the Edge Transit Gateway name.<br />The Edge Transit Gateway Details page opens.
              3. Click the **Settings** tab. Expand **Border Gateway Protocol (BGP)**.
              4. Scroll to **AS Path Prepend**.
                 * For all BGP connections: enter values in **Prepend AS Path (Per Gateway)**.
                 * For one connection: select the connection in **Connection**, then enter values in **Prepend AS Path (Per Connection)**.
              5. Click **Save**.
            </Accordion>

            <Accordion title="Configure Preserve AS Path (BGP)">
              Applies when **Manual BGP Advertised CIDR List** is set.

              * **On:** AS Path is preserved; manual advertised CIDRs are not advertised if they are no longer in the best route DB.
              * **Off:** AS Path is stripped on advertisements to neighbors.

              To set Preserve AS Path:

              1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Edge Gateways** > **Transit Gateways**.<br />A table appears with the list of Edge Transit Gateways.
              2. Click the Edge Transit Gateway name.<br />The Edge Transit Gateway Details page opens.
              3. Click the **Settings** tab. Expand **Border Gateway Protocol (BGP)**.
              4. Set **Preserve AS Path** as needed.
              5. Click **Save**.
            </Accordion>

            <Accordion title="Configure BGP ECMP">
              With multiple BGP connections, the Controller normally picks one best route. **BGP ECMP** can merge equal routes and load-share traffic by ECMP hashing.

              To enable BGP ECMP:

              1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Edge Gateways** > **Transit Gateways**.<br />A table appears with the list of Edge Transit Gateways.
              2. Click the Edge Transit Gateway name.<br />The Edge Transit Gateway Details page opens.
              3. Click the **Settings** tab. Expand **Border Gateway Protocol (BGP)**.
              4. Turn **BGP ECMP** **On**.
              5. Click **Save**.
            </Accordion>

            <Accordion title="Configure BGP Polling Time">
              BGP routes are reported to the Controller on a timer (default 50 seconds). Shorter values can speed convergence.

              To change BGP polling time:

              1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Edge Gateways** > **Transit Gateways**.<br />A table appears with the list of Edge Transit Gateways.
              2. Click the Edge Transit Gateway name.<br />The Edge Transit Gateway Details page opens.
              3. Click the **Settings** tab. Expand **Border Gateway Protocol (BGP)**.
              4. Set **BGP Polling Time** between **10** and **50** seconds.
              5. Click **Save**.
            </Accordion>

            <Accordion title="Configure BGP Hold Time">
              **Hold time** is how long the gateway waits for BGP messages before treating the neighbor as down.

              To set BGP hold time:

              1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Edge Gateways** > **Transit Gateways**.<br />A table appears with the list of Edge Transit Gateways.
              2. Click the Edge Transit Gateway name.<br />The Edge Transit Gateway Details page opens.
              3. Click the **Settings** tab. Expand **Border Gateway Protocol (BGP)**.
              4. Set **BGP Hold Time** between **12** and **180** seconds.
              5. Click **Save**.
            </Accordion>

            <Accordion title="Enable Site2Cloud RX Balancing (BGP)">
              <Note>**Note:** Available only on Aviatrix Transit Gateways in AWS on **C5** and **C5n** sizes (not **c5.large** or **c5n.large**).</Note>

              Increases forwarding throughput for BGP-over-GRE Site2Cloud traffic. A brief (sub-second) packet loss can occur when toggling this setting.

              To enable Site2Cloud RX Balancing:

              1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Edge Gateways** > **Transit Gateways**.<br />A table appears with the list of Edge Transit Gateways.
              2. Click the Edge Transit Gateway name.<br />The Edge Transit Gateway Details page opens.
              3. Click the **Settings** tab. Expand **Border Gateway Protocol (BGP)**.
              4. Turn **Site2Cloud (S2C) RX Balancing** **On**.
              5. Click **Save**.
            </Accordion>

            <Accordion title="Enable Gateway Learned CIDR Approval">
              With **Gateway Learned CIDR Approval** **On**, the Controller emails the administrator to approve learned CIDRs before propagation.

              **Gateway mode** applies approval to all BGP connections. **Connection mode** targets one BGP connection.

              To enable Gateway Learned CIDR Approval:

              1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Edge Gateways** > **Transit Gateways**.<br />A table appears with the list of Edge Transit Gateways.
              2. Click the Edge Transit Gateway name.<br />The Edge Transit Gateway Details page opens.
              3. Click the **Settings** tab. Expand **Border Gateway Protocol (BGP)**.
              4. Turn **Gateway Learned CIDR Approval** **On**.
              5. Choose **Gateway** or **Connection**. For **Connection**, select the BGP connection in **Connection**.
              6. Click **Save**.
            </Accordion>
          </Accordion>
        </AccordionGroup>
      </Tab>
    </Tabs>
  </Tab>

  <Tab title="Devices">
    ## Purpose

    The **Devices** page shows a table of on-premises devices onboarded for hybrid connectivity. You can view device details, onboard new devices, manage proxy profiles for device onboarding, and edit or delete devices.

    ## Elements

    <Frame>
      <img src={"/images/reference/ui/cloud-fabric/hybrid-devices.png"} alt="Hybrid Cloud: Devices" width="100%" />
    </Frame>

    * **Onboard Device button**: Starts workflow to onboard a new on-premises device.
    * **Proxy Profiles button**: Opens a window to manage proxy profiles for device onboarding.
    * **Devices table**: Displays onboarded device Name, Serial Number, SKU/Model, Status, Status Updated At, and Actions.
    * **Edit button**: Opens configuration panel to modify device settings.
    * **Delete button**: Deletes the selected device.

    ## Actions

    <AccordionGroup>
      <Accordion title="View Onboarded Devices">
        To view the list of onboarded devices and their details:

        1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Devices**.<br />The Devices page appears with a table of onboarded devices.
        2. Optionally, use **Search**, **Filter**, or **Select columns** to find or customize the view.
        3. Click a device name to view its details.

        The table displays onboarded devices with their configurations and status.

        ### Parameter Details

        | CoPilot Parameter Name | Description                                |
        | ---------------------- | ------------------------------------------ |
        | Name                   | Name assigned to the device.               |
        | Serial Number          | Serial number of the device.               |
        | SKU/Model              | Hardware model or SKU of the device.       |
        | Device Type            | Type of device (physical or virtual).      |
        | Status                 | Current connectivity status of the device. |
        | Status Updated At      | Timestamp of the last status update.       |
      </Accordion>

      <Accordion title="Onboard Device">
        To onboard a new on-premises device for hybrid connectivity:

        1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Devices**.<br />The Devices page appears with a table of onboarded devices.
        2. Click **Onboard Device**.<br />The Onboard Device wizard or form appears.
        3. Provide Name, Platform, Device Configuration, Serial Number, and interface settings. Refer to the Parameter Details table below.
        4. Optionally, configure a Proxy Profile if the device uses a proxy for internet access.
        5. Click **Save** or **Onboard**.

        A notification appears when the device is onboarded. The device appears in the Devices table once it connects to the Aviatrix Platform.

        ### Parameter Details

        **Device Details**

        | CoPilot Parameter Name | Description                                                                    |
        | ---------------------- | ------------------------------------------------------------------------------ |
        | Name                   | A name to identify the edge device.                                            |
        | Platform               | The Aviatrix Edge Platform account where to onboard the device.                |
        | Device Configuration   | Hardware configuration (e.g., DELL Poweredge 1x E810, DELL Poweredge 2x E810). |
        | Serial Number          | The serial number of the edge device.                                          |

        **Device Interface Configuration**

        | CoPilot Parameter Name | Description                                              |
        | ---------------------- | -------------------------------------------------------- |
        | Physical Interface     | The physical interface port.                             |
        | Function               | The physical port function: WAN, LAN, or MGMT.           |
        | DHCP                   | **Off** for static IP. **On** for dynamic IP allocation. |

        **Management Port Configuration (when DHCP is Off)**

        | CoPilot Parameter Name | Description                                        |
        | ---------------------- | -------------------------------------------------- |
        | Interface CIDR         | The static IP address of the Management interface. |
        | Gateway IP             | The Management default gateway IP address.         |
        | Primary DNS            | The primary DNS server IP address.                 |
        | Secondary DNS          | Optional secondary DNS server IP address.          |
      </Accordion>

      <Accordion title="Manage Proxy Profiles">
        To manage proxy profiles for device onboarding:

        1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Devices**.<br />The Devices page appears.
        2. Click **Proxy Profiles**.<br />The Proxy Profiles window appears.
        3. Click **+ Proxy Profile** to create a new profile, or use **Edit** or **Delete** on an existing profile.
        4. Provide Name, Transparent Mode, Proxy Server IP, Proxy Port, and optional Proxy Certificate.
        5. Click **Save**.

        Proxy profiles can be associated with the Management interface when onboarding a device. Devices require internet access to communicate with the Aviatrix Platform; use a proxy profile when traffic is routed through a proxy server.

        ### Parameter Details

        | CoPilot Parameter Name | Description                                    |
        | ---------------------- | ---------------------------------------------- |
        | Name                   | A name for the proxy profile.                  |
        | Transparent Mode       | Enable or disable transparent proxy mode.      |
        | Proxy Server IP        | IP address of the proxy server.                |
        | Proxy Port             | Port number for the proxy server.              |
        | Proxy Certificate      | Optional certificate for proxy authentication. |
      </Accordion>

      <Accordion title="Edit Device">
        To edit an onboarded device:

        1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Devices**.<br />The Devices page appears with a table of onboarded devices.
        2. Locate the device and click the **Edit** icon on the row.<br />The Edit Device dialog appears.
        3. Make the configuration changes needed (e.g., interface settings, proxy profile).
        4. Click **Save**.

        A notification appears confirming the changes to the device.
      </Accordion>

      <Accordion title="Delete Device">
        To delete an onboarded device:

        1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Devices**.<br />The Devices page appears with a table of onboarded devices.
        2. Locate the device and click the **Delete** icon on the row.
        3. Confirm the deletion in the dialog.

        A notification appears when the device is deleted. You must remove any Edge Gateways deployed on the device before deleting it.
      </Accordion>
    </AccordionGroup>
  </Tab>

  <Tab title="Platforms">
    ## Purpose

    The **Platforms** page shows a table of integrated platforms for hybrid connectivity and their details. You can view platform details, add new platform accounts (Aviatrix Edge or Network Service Provider), edit platform settings, and delete platforms.

    ## Elements

    <Frame>
      <img src={"/images/reference/ui/cloud-fabric/hybrid-platforms.png"} alt="Hybrid Cloud: Platforms" width="100%" />
    </Frame>

    * **+ Platform button**: Starts workflow to integrate a new platform.
    * **Platform table**: Displays integrated platform Name, Type, Account Info, and Actions.
    * **Edit button**: Opens configuration panel to modify platform settings.
    * **Delete button**: Deletes the selected platform.

    ## Actions

    <AccordionGroup>
      <Accordion title="View Platforms">
        To view the list of integrated platforms and their details:

        1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Platforms**.<br />The Platforms page appears with a table of integrated platforms.
        2. Click a platform name to view its details.

        The table displays integrated platforms with their configurations and integration status.

        ### Parameter Details

        | CoPilot Parameter Name | Description                                                                     |
        | ---------------------- | ------------------------------------------------------------------------------- |
        | Name                   | Name assigned to the platform.                                                  |
        | Platform Type          | Type of platform (Aviatrix Edge, Network Service Provider (NSP), Self Managed). |
        | Account Info           | Details of the account used for platform integration.                           |
        | Integration Status     | Indicates if the platform is successfully integrated.                           |
      </Accordion>

      <Accordion title="Add Platform">
        To add a new platform account for hybrid connectivity:

        1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Platforms**.<br />The Platforms page appears with a table of integrated platforms.
        2. Click **+ Platform**.<br />The Add Platform dialog appears.
        3. Enter a name for the account (for example, OnPremises, Equinix, or Megaport).
        4. Select the platform type: **Aviatrix Edge** for the Aviatrix Edge Platform, or **Network Service Provider (NSP)** for Equinix or Megaport.
        5. If **NSP** is selected, choose **Equinix** or **Megaport** from the dropdown.
        6. Click **Connect**.

        The platform account is registered. You can use it when deploying Edge Gateways on the selected platform.

        ### Parameter Details

        | CoPilot Parameter Name | Description                                                                                                                               |
        | ---------------------- | ----------------------------------------------------------------------------------------------------------------------------------------- |
        | Name                   | A name for the platform account (for example, OnPremises, Equinix, Megaport).                                                             |
        | Platform Type          | **Aviatrix Edge**: For the Aviatrix Edge Platform. **Network Service Provider (NSP)**: For Equinix Network Edge or Megaport Virtual Edge. |
        | NSP Provider           | When NSP is selected: **Equinix** for Equinix Network Edge, **Megaport** for Megaport Virtual Edge.                                       |
      </Accordion>

      <Accordion title="Edit Platform">
        To edit a platform account:

        1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Platforms**.<br />The Platforms page appears with a table of integrated platforms.
        2. Locate the platform and click the **Edit** icon on the row.<br />The Edit Platform dialog appears.
        3. Make the configuration changes needed.
        4. Click **Save**.

        A notification appears confirming the changes to the platform.
      </Accordion>

      <Accordion title="Delete Platform">
        To delete a platform account:

        1. Go to **Cloud Fabric** > **Hybrid Cloud** > **Platforms**.<br />The Platforms page appears with a table of integrated platforms.
        2. Locate the platform and click the **Delete** icon on the row.
        3. Confirm the deletion in the dialog.

        A notification appears when the platform is deleted. You must remove any Edge Gateways deployed on the platform before deleting it.
      </Accordion>
    </AccordionGroup>
  </Tab>
</Tabs>
