9.0.0
Release Date: 12 May 2026 Follow these links to learn about what’s new in this release: Deprecation Notices / Removals in Release 9.0.0 New and Enhanced Features in Release 9.0.0 Early Access Features in Release 9.0.0 Behavior Changes in Release 9.0.0Deprecation Notices / Removals in Release 9.0.0
S2C Telemetry / RRD from Controller
Unused S2C telemetry fields and the legacy RRD database dependency have been removed from the Controller. No user action required. For details on which fields were retired and the stability impact, see Removal of S2C Telemetry Fields and RRD .New and Enhanced Features in Release 9.0.0
Gateway Drain/Undrain
Image upgrade, gateway delete, and gateway resize operations now drain HA gateway pairs before the operation begins and undrain only after the data plane has converged:- The gateway is removed from Aviatrix routing and from cloud route tables before the operation, so traffic flows through the HA peer.
- The gateway returns to service only after tunnels and routing are stable.
- Drain and undrain require an HA peer. Single-gateway operations are not protected by this sequence.
Upgrade Plan and Upgrade Groups
CoPilot consolidates Controller and gateway upgrade actions on a single Upgrade Plan page under Administration > Upgrade. You can organize gateways into upgrade groups using preset templates by Cloud, Account, Region, and Image Version. HA pairs are split across subgroups automatically. Upgrade Groups apply to both software and image upgrades.Validated Upgrade Path Framework
The Controller and CoPilot validate the upgrade path between the source and target versions, surface the intermediate hops required, and block paths that are not supported. This guidance is driven by a versioned configuration that does not require code changes to support new releases.DCF East-West with AWS TGW (Bump-in-the-Wire)
Inter-VPC traffic inspection via DCF for existing AWS TGW environments:- Aviatrix spoke gateways are inserted into the traffic path with no re-architecture of the existing TGW.
- Supports East-West inspection and selective egress NAT in the same VPC.
- AWS only in 9.0; no Terraform support.
DCF IPS (Ingress/Egress) & TLS Inspection
Suricata-based inline detection and prevention with TLS decryption:- Three operational modes: IPS Only, TLS Decrypt Only, IPS + TLS Decrypt for full encrypted threat visibility
- IPS profile is global with one active at a time; default feed is ET Open with custom rule feed support
- TLS profile is per-rule with per-rule trust bundles
- MITM CA is global with bring-your-own or Aviatrix-generated default
- Terraform and API automation supported
Explicit Azure Route Table Selection for DCF Egress
Replaces implicit route detection with explicit Azure route table selection for egress:- Select which Azure route tables receive the default route via the Aviatrix spoke gateway when Single IP SNAT is enabled.
- On upgrade from 8.2, previously implicit private route tables are migrated in
CoPilot and surfaced as explicit selections. Existing Terraform configurations
are not auto-migrated; update them after the provider upgrade to declare
private_route_table_configand avoid plan drift. - The Controller saves and restores the original default route on disable or deselect.
- Terraform support is added on
aviatrix_spoke_gateway,aviatrix_transit_gateway,aviatrix_spoke_group,aviatrix_transit_group, andaviatrix_azure_spoke_native_peering.
Automated Default Route Management for GCP DCF Egress
Simplified egress for GCP regional VPCs:- Programs the default route without the
avx-snat-noiptag, so all VMs egress via the Aviatrix spoke when enabled. - On software upgrade from 8.2, the existing behavior is preserved. New behavior is triggered by routing changes.
- Regional VPCs only. GCP Global VPCs are unchanged.
DCF Logging Enhancements (Session & L4 Logging)
Session and L4 logging now available in policy logs for improved troubleshooting and compliance reporting.K8S Discovery (Enabled by Default)
Kubernetes workload discovery is now enabled by default for SmartGroup policy enforcement.Smart Gateways Phase 2
Advances fast routing convergence with distributed route computation:- GoBGP policy support for cloud network route advertisement
- MTT (Multi-Tier Transit) support for cloud network routes
- Best route computation on each gateway
- Overlay CIDR collection with segmentation support
- Supports headless mode; controller only needed for bringing new gateways into the fabric
IPv6 Capability Phase 2
Expands dual-stack (IPv4 + IPv6) support across the platform:- GCP gateway support
- Telemetry support
- AWS-Gov and Azure-Gov support
- Equinix Edge support (LAN interface only)
- ULA (Unique Local Address) support
- S2C segmentation support
- FireNet egress support
- Dual-stack with IPv4 cloud network including High Performance Encryption (HPE) for spokes and transits
Active Mesh 4.0 Phase 2
Enhanced multicloud resiliency and operational flexibility:- All gateways in a group are equal; primary gateway can be safely deleted
- Dynamic HPE toggle at gateway group level with rolling transition
- Mixed HPE/non-HPE mode supported during transition if address space is insufficient
- Unified Gateway API with Terraform support
First-Hop VRF Support for Overlapping CIDRs
Kernel VRF namespace isolation for overlapping routes at Transit Gateway:- Enables overlapping CIDRs from multiple S2C connections in different segments
- Each domain gets its own kernel VRF namespace
- First-hop only. S2C on Transit GW with Cloud Transit and Edge Transit support.
- No FireNet support.
Proxy ID for Route-Based Site2Cloud
IPSec traffic selectors for route-based S2C tunnels:- Configures specific local and remote traffic selectors instead of default 0.0.0.0/0
- Enables route-based tunnels to interoperate with policy-based peers
- Toggle on/off and edit CIDRs on existing connections without tunnel recreation
- Terraform, API, and CoPilot support
S2C on Horizontally Scaled Transit
Site-to-Cloud connections are now supported on horizontally scaled (Smart Gateway) transit groups:- S2C can be enabled on a scaled transit group with 3 or more gateways.
- S2C tunnels terminate on the first two gateways in the scaled group.
- FireNet on horizontally scaled transit is not supported in 9.0.
Dell R470 for AEP Edge
New hardware platform replacing end-of-support Dell R450:- Broadcom NICs with new EvE OS image and g4 gateway image.
- 25G NIC support in 9.0.
- Transit Edge and Spoke Edge supported.
- Requires Controller 8.0 or later.
Image Upgrade for Self-Managed and Equinix Edge Gateways
Edge gateway image upgrade without deleting gateways on Aviatrix Controller:- Regenerate cloud-init data and launch a new Edge VM with a compatible image
- Image upgrade pushes all configuration to the new gateway VM
- CoPilot and API support; cloud-init downloadable for all edge gateways
- Must complete in the same maintenance window. Not hitless; requires traffic drain.
Per-Firewall Vendor Integration through Firewall Manager
FireNet now supports per-firewall Panorama template and template stack:- Each firewall attached to the same FireNet gateway can have its own template and template stack
- Enables heterogeneous firewall configurations within the same FireNet gateway
Restrictive Firewall Management Security Groups for Azure
Aviatrix now scopes inbound rules on Azure FireNet firewall management interfaces to the Aviatrix Controller IP, replacing open0.0.0.0/0 rules. This
extends the same protection AWS FireNet has had since 8.x.
- Applies to Palo Alto Networks, Check Point, and Fortinet firewalls in Azure
- Egress and LAN interface rules are unchanged
- Controller IP source is updated automatically when the Controller IP changes
Default Route from Transit FireNet to Edge Spoke
Allows default route propagation from Transit FireNet to Edge Spoke gateways.Early Access Features in Release 9.0.0
Centralized Security Hub VPC (AWS)
Deploy Aviatrix as a centralized security hub VPC for existing TGW deployments in AWS:- Aviatrix auto-provisions all VPC infrastructure including subnets, GWLB, endpoint services, route tables, and cross-zone load balancing.
- Supports AZ affinity to reduce cross-zone transfer charges.
- API only in this release.
DCF on Edge (Spoke & Transit)
Distributed Cloud Firewall enforcement on Edge gateways:- Edge as Spoke: L4 filtering, L7 filtering (SNI-based hostname), TLS Decryption
- Edge as Transit: L4 filtering only
BGPoLAN for Azure China
BGPoLAN now available in Azure China (21Vianet):- Same BGPoLAN architecture as global Azure regions
- Transit GW with BGP over LAN for DC-to-cloud connectivity
DCF Policy Audit
Structured diffs and change attribution (who/what/when) for DCF entities:- Exportable via API for compliance and CI governance pipelines
DCF for Serverless Resources
Extends SmartGroups and DCF policies to serverless compute:- Supports AWS Lambda, AWS ECS/Fargate, Azure Functions, Azure Container Apps, GCP Cloud Functions, and GCP Cloud Run.
- SmartGroups define serverless resources by name, tags, region, and account.
- SmartGroup membership updates automatically for ephemeral workloads.
Behavior Changes in Release 9.0.0
Gateway Drain/Undrain on Operations
Image upgrade, gateway delete, and resize operations now drain the gateway before proceeding. Cloud route tables are updated in-place to direct traffic to the HA peer before the operation begins. If the operation fails, the gateway stays drained. It returns to service only after connectivity is up, configuration is synced, and all tunnels are back.Active Mesh 4.0 High Performance Encryption (HPE) Toggle
Enabling High Performance Encryption (HPE) replaces existing non-HPE gateways with new HPE-enabled gateways. Mixed HPE/non-HPE mode is supported during the transition if address space is insufficient.Edge Image Upgrade Workflow
Self-managed and Equinix Edge gateways now support image upgrade without deleting the gateway from the Controller. Cloud-init data must be regenerated and a new Edge VM launched with a compatible image. For Equinix Edge gateways, BGP peering connections must be deleted and recreated after the upgrade.GCP Regional VPCs: Local Egress by Default
Before 9.0, only VMs tagged withavx-snat-noip used the Spoke Gateway for
egress. In 9.0, all workloads in the Regional VPC use the Spoke Gateway for
egress by default: both private instances and public instances (those with an
external IP). This applies to any GCP SNAT-related feature, including Egress
FireNet, and to serverless services such as Cloud Run and Cloud Functions.
Global VPCs are not affected.
If any workloads need direct internet access without going through Aviatrix (for
example, bastion hosts, automation runners, or public instances that should
reach the internet directly), add your own network-tag-based routes for those
workloads and tag the instances accordingly, so their traffic bypasses the Spoke
Gateway.
Upgrade Impact
Azure VNET: Explicit Route Table Selection for Local Egress
Before 9.0, the Controller auto-detected route tables with a 0.0.0.0/0 default route and next-hop set to None, then overwrote them with a route to the Aviatrix gateway. This sometimes modified unintended tables and could cause traffic disruptions. In 9.0, you choose which Azure route tables receive the default route to the Aviatrix gateway. The Controller saves the original route for each selected table and restores it when you disable SNAT or deselect the table.Upgrade Impact
Terraform example: