Skip to main content
The Vendor Integration function allows you to log into a firewall or firewall manager and change the route table on the firewall to program the routing for Transit FireNet, or to change routing if a gateway in Transit FireNet fails. You can also use Vendor Integration to configure the RFC 1918 and non-RFC 1918 routes between the Aviatrix Gateway and the vendor’s firewall instance. To turn On IPv6 on an existing FireNet, revoke the existing Vendor Integration settings, enable IPv6 on the FireNet, and then reconfigure Vendor Integration. Controller Version 9.0 extends IPv6 FireNet vendor support to Fortinet and Check Point, in addition to Palo Alto Networks (supported from Release 8.2). IPv6 Vendor Integration applies to Palo Alto Networks standalone firewalls (without Panorama) from Release 8.2, and to Fortinet and Check Point from Release 9.0. The Controller blocks attaching firewall instances whose firmware does not support IPv6 to an IPv6-enabled FireNet Gateway.
IPv6 vendor integration in Azure is currently not functional. If you require vendor-driven IPv6 route programming in Azure, configure IPv6 routes manually in the firewall.
You can only configure information on this dialog if a firewall is already attached to the Transit FireNet.

Configuring Vendor Integration

  1. From the Security > FireNet Gateways tab, click the vertical ellipsis icon menu in a FireNet Gateway row and select Manage Vendor Integration.
  2. In the Vendor Integration dialog, select Through Firewall or Through Firewall Manager. You should only select the latter if the Vendor is a Palo Alto firewall (managed by Panorama).
Firewall Vendor Integration
  1. Configure the following:
  1. Click Save.

Revoking Vendor Integration

You cannot revoke vendor integration for FireNet gateways that have the Generic vendor selected.
To revoke Vendor Integration:
  1. Select Vendor Integration as per step 1 above, and then click Revoke Integration on the dialog.
  2. When prompted about being sure you want to revoke, click Revoke.

Syncing Routes to Firewall

The Vendor Integration tab only displays for a Transit FireNet if you have configured a Firewall Manager (Panorama) and attached it to this Transit FireNet.
You can click Sync Routes to Firewall on the FireNet Gateway Vendor Integration tab (you must configure vendor integration first) or the details panel for the firewall, to ensure that the FireNet routes are synced to the selected firewall.
You can also sync routes to the firewall from the Security > FireNet > Firewall details tab.
Since vendor integration requires that the firewall be pinged periodically, you should configure the ‘ping’ ability in the respective firewall UIs.
You can also sync routes to the firewall from the Security > FireNet > Firewall tab (click a firewall to see its details, and then click Sync Routes to Firewall).