Skip to main content
The Aviatrix data plane is the network layer that handles actual traffic forwarding and processing across your cloud infrastructure. This section provides an overview of the data plane components and their roles in the Aviatrix platform.

What is the Data Plane?

The data plane (also known as the forwarding plane) is responsible for:
  • Traffic Forwarding: Moving packets between network endpoints based on routing decisions
  • Encryption/Decryption: Handling IPsec and other encryption protocols for secure communication
  • Network Address Translation (NAT): Performing source and destination NAT operations
  • Traffic Inspection: Supporting integration with firewall and security services
  • Quality of Service (QoS): Managing traffic prioritization and bandwidth allocation

Data Plane Components

The Aviatrix data plane consists of several key components:

Gateways

Aviatrix Gateways are the primary data plane elements deployed in your cloud environments. They handle:
  • VPN tunnel termination
  • Traffic routing between VPCs/VNets
  • Encryption and decryption of traffic
  • Network segmentation enforcement
For more information, see Gateway Overview.

Edge Gateways

Edge Gateways extend the Aviatrix data plane to on-premises environments and branch locations:
  • Connect physical data centers to cloud networks
  • Support high-availability deployments
  • Provide consistent networking features across hybrid environments
Learn more about Edge deployments in the Edge Spoke Overview.

ActiveMesh

ActiveMesh is the Aviatrix technology that enables:
  • Active-active gateway deployment for high availability
  • Optimal path selection for traffic
  • Automatic failover without manual intervention
For architecture details, see ActiveMesh Design Notes.

Data Plane vs Control Plane

AspectData PlaneControl Plane
FunctionForwards trafficMakes routing decisions
ComponentsGateways, tunnelsController, CoPilot
PerformanceHigh throughput, low latencyManagement operations
ScalingHorizontal (more gateways)Vertical (larger instance)

Key Features

High Performance

  • Support for high-throughput instances
  • Hardware acceleration where available
  • Optimized packet processing

Security

  • End-to-end encryption
  • Integration with cloud-native firewalls
  • Support for third-party security appliances

Visibility

  • Flow logging and analytics
  • Real-time monitoring through CoPilot
  • Detailed traffic statistics