Skip to main content
Aviatrix Transit Gateways, BGP-enabled Spoke Gateways, and Edge Gateways dynamically learn BGP routes from remote peers. These learned routes are reported to the Aviatrix Controller, which then propagates and programs the route entries into the Spoke VPC or VNet route tables. For scenarios such as a VPN connecting to a partner network, you may require an approval process before dynamically learned CIDRs propagate to the Spoke VPC or VNet. This prevents undesirable routes, such as the default route (0.0.0.0/0), from entering your network and causing outages. The Learned CIDR Approval feature enforces this process. When enabled, dynamically learned routes from all remote peers trigger an email notification to the Controller administrator. To propagate the learned routes to the Spoke VPC or VNet route table, the Controller administrator should log in to the CoPilot and approve the learned routes. Transit Approval Gateway Mode Gateway mode is the default approval mode. In this mode, learned CIDR approval applies to all BGP connections configured on the gateway. Connection Mode Connection mode enables you to select a specific BGP connection for approval.
Connection Mode is only available for Transit Gateways. BGP Spoke Gateways only support Gateway Mode.
To propagate all the dynamically learned routes to the Spoke VPC/VNet route table, set the Manual Approval toggle to Off. See Enabling Gateway Learned CIDR Approval for more information.

Enabling Gateway Learned CIDR Approval

To set an approval process for the dynamically learned CIDRs on the Transit or Spoke Gateway, in Aviatrix CoPilot:
  1. Go to Cloud Fabric > Gateways > Transit Gateways or Spoke Gateways tab, a table of gateways and their details appears.
  2. In the table, click the gateway name to enable learned CIDR approval.
  3. Go to the gateway’s Settings tab and expand Border Gateway Protocol (BGP) section.
    The gateway’s Settings tab is in the same row as the Details, Instances, and Attachments tabs.
  4. Locate the Manual Learned CIDR Approval card and set Manual Approval toggle to On.
    If the Manual Approval toggle is set to Off, all learned routes on the gateway from its remote peer are approved.
    • To approve learned CIDRs for all BGP connections on the Transit Gateway or Spoke Gateway, select Gateway Level. * To approve learned CIDRs for a specific BGP connection on the Transit Gateway, select Connection Level. An On External Connections dropdown menu appears.
    Connection Level is only available for Transit Gateways. BGP Spoke Gateways only support Gateway Level.
    • From the On External Connections dropdown menu, select one or more BGP connections to enable learned CIDR approval. * Click Save.
An approval process is set for the dynamically learned CIDRs on the Transit or Spoke Gateway.

Approving Learned CIDRs in CoPilot

When Gateway Learned CIDR Approval is enabled, an email notification is sent to the Aviatrix Controller administrator to approve the learned CIDRs. On approval the learned CIDRs are propagated to the Spoke VPC or VNet route table.

Approving Learned CIDRs Enabled for a Gateway

The following are the types of approval for a gateway:
  • Manual Approval: All learned CIDRs from all BGP connections on the gateway require approval.
  • Pre-Approval: You can add one, multiple, or a range of CIDRs to a pre-approved CIDRs rule. Any learned CIDR that matches a pre-approved CIDR in the rule is automatically approved and propagated to the Spoke VPC or VNet route table without requiring manual approval.

Manual Approval

For Manual Approval of the learned CIDR, in Aviatrix CoPilot:
  1. Go to Cloud Fabric > Gateways > Transit Gateways or Spoke Gateways tab, a table of gateways and their details appears.
  2. In the table, click the gateway name to approve CIDRs.
  3. Click the Route Approval tab. A table of learned CIDRs appears.
    The Route Approval tab only appears for a gateway if the Manual Approval toggle is set to On for the gateway.
  4. In the table, select the CIDRs and click + Approval Rules.
  5. To use the Free Range Routing (FRR) syntax, set the FRR Syntax toggle to On. See FRR Syntax for more information.
  6. To add CIDRs using a relationship operator between a Base CIDR and Prefix Length instead of using FRR syntax, set the FRR Syntax toggle to Off.
  7. Click +Rule. A new row appears in the Create Approval Rules table.
  8. In the new row, enter the Base CIDR, select the relationship operator, and enter the Prefix Length.
  9. Click Approve.
Examples: The CIDRs learned from the remote peer a approved.

Pre-Approval

For Pre-Approval of the learned CIDRs:
  1. Go to Cloud Fabric > Gateways > Transit Gateways or Spoke Gateways tab, a table of gateways and their details appears.
  2. In the table, click the gateway name to approve CIDRs to propagate.
  3. Click the Route Approval tab. A table of learned CIDRs appears.
  4. Click Approval Rules.
  5. Click + Approval Rule. The Create Approval Rules dialog appears.
  6. Set the FRR Syntax toggle to On to use the Free Range Routing (FRR) syntax. See FRR Syntax for more information.
  7. To add CIDRs using a relationship operator between a Base CIDR and Prefix Length instead of using FRR syntax, set the FRR Syntax toggle to Off.
  8. Click +Rule. A new row appears in the Create Approval Rules table.
  9. In the new row, enter the Base CIDR, select the relationship operator, and enter the Prefix Length.
  10. Click Save Draft.
  11. Click Commit.
Examples: The added CIDRs are pre-approved when learned from the remote peer.

Approving Learned CIDRs Enabled for a BGP Connection

The following are the types of approval for an external connection:
  • Manual Approval: All learned CIDRs from all BGP connections on the external connection require approval.
  • Pre-Approval: You can add one, multiple, or a range of CIDRs to a pre-approved CIDRs rule. Any learned CIDR that matches a pre-approved CIDR in the rule is automatically approved and propagated to the Spoke VPC or VNet route table without requiring manual approval.
If you select an external connection for Learned CIDR Approval (either from the gateway or from the external connection’s settings tab), CoPilot displays a Route Approval tab for that connection.

Manual Approval

For Manual Approval of the learned CIDR, in Aviatrix CoPilot:
  1. Go to Networking > Connectivity > External Connections (S2C) tab. A table of external connections and their details appears.
  2. Click the connection name to approve CIDRs.
  3. Click the Route Approval tab, a table of learned CIDRs appears.
    The Route Approval tab only appears for the connection if the Manual Learned CIDR Approval toggle is set to On for the connection.
  4. In the table, select the CIDRs and click + Approval Rules.
  5. Set the FRR Syntax toggle to On to use the Free Range Routing (FRR) syntax. See FRR Syntax for more information.
  6. To add CIDRs using a relationship operator between a Base CIDR and Prefix Length instead of using FRR syntax, set the FRR Syntax toggle to Off.
  7. Click +Rule. A new row appears in the Create Approval Rules table.
  8. In the new row, enter the Base CIDR, select the relationship operator, and enter the Prefix Length.
  9. Click Save Draft.
  10. Click Commit.
Examples: The CIDR learned from the remote peer is approved.

Pre-Approval

For Pre-Approval of the learned CIDRs:
  1. Go to Networking > Connectivity > External Connections (S2C) tab. A table of external connections and their details appears.
  2. Click the connection name to approve CIDRs.
  3. Click the Route Approval tab.
  4. Click Approval Rules.
  5. Click + Approval Rule. The Create Approval Rules dialog appears.
  6. Set the FRR Syntax toggle to On to use the Free Range Routing (FRR) syntax. See FRR Syntax for more information.
  7. To add CIDRs using a relationship operator between a Base CIDR and Prefix Length instead of using FRR syntax, set the FRR Syntax toggle to Off.
  8. Click +Rule. A new row appears in the Create Approval Rules table.
  9. In the new row, enter the Base CIDR, select the relationship operator, and enter the Prefix Length.
  10. Click Save Draft.
  11. Click Commit.
Examples: The added CIDRs are pre-approved when learned from the remote peer.

FRR Syntax

Use Free Range Routing (FRR) syntax with “ge” (greater than or equal to) and “le” (less than or equal to) to match a range of prefixes. This approves multiple routes without needing to specify each exact match. For example, 10.1.0.0/16 ge 16 le 24 matches any prefix within the 10.1.0.0/16 block that has a subnet mask between /16 and /24, where /16 and /24 are inclusive. Special Cases
  • 0.0.0.0/0 le 32 matches all CIDRs.
  • 0.0.0.0/0 ge 0 only matches the exact default route.
Examples: