Creating a Public Subnet Filtering Gateway (AWS)
To create a Public Subnet Filtering (PSF) Gateway:
-
In CoPilot, navigate to Cloud Fabric > Gateways > Specialty Gateways tab.
-
Click + Gateway and select Public Subnet Filtering Gateway.
-
Provide the following information to set up your Public Subnet Filtering Gateway.
Parameter Description Name
Enter a name for this new PSF gateway.
Cloud
Use the dropdown menu to select AWS Standard, GovCloud, or China.
Account
Select the cloud access account for this gateway.
Region
Select the cloud region in which to create this gateway.
VPC
Select the VPC in the selected region in which to create this gateway.
Instance Size
Select the gateway instance size.
The gateway instance size must be at least t3.medium if you want to create a DCF rule to apply to a PSF gateway, and you select Intrusion Detection or TLS Decryption when creating that rule. Attach to Unused Subnet
Aviatrix Controller creates a public subnet and creates a route table associated with the subnet to launch the PSF gateway.
Route Table
Select route tables whose associated public subnets are protected.
Route tables must be selected here to be monitored and enforced by any DCF rules the PSF gateway is part of. -
Click Save.
After the Public Subnet Filtering Gateway is deployed, Ingress traffic from IGW is routed to the gateway in a pass through manner. Egress traffic from instances in the protected public subnets is routed to the gateway in a pass through manner.