Aviatrix Aviatrix Documentation
Resources
Terraform Support
Request Demo
CoPilot
Latest Versions
  • Controller
  • CoPilot
      • What’s New
      • Aviatrix CoPilot Overview
        • What’s New in CoPilot?
        • Aviatrix Feature Modes
        • Aviatrix Feature Availability by Controller Version
        • Aviatrix CoPilot Features
        • Aviatrix CoPilot Platform
      • Getting Started
        • Planning Your CoPilot Deployment
          • CoPilot Platform Requirements
          • CoPilot Deployment Methods
          • CoPilot Simple Deployment
          • CoPilot Fault Tolerant Deployment
        • CoPilot Deployment
          • Deploy CoPilot from your Controller UI (AWS Only)
          • Deploy CoPilot using Terraform
          • Deploy CoPilot from the Marketplace
        • Post CoPilot Deployment Tasks
          • Initial Setup of CoPilot
          • CoPilot Settings to be Enabled in Controller
          • Verify the CoPilot Deployment and the Connectivity with Controller
          • (Optional) Enable CoPilot Add-on Features
          • Set Up SAML Login for CoPilot
        • Logging in to CoPilot
        • Using Aviatrix CoPilot
          • CoPilot Navigation Menu
          • Setting CoPilot UI Preferences
        • Deleting a CoPilot instance
      • Accounts and Users
        • CoPilot User Account Administration
        • Logging in to CoPilot
        • Users and Permissions
        • Creating a Cloud Account
        • Auditing a Cloud Account
        • Deleting a Cloud Account
        • AWS IAM Overview
          • Account with Access Key for AWS China Accounts
      • Building Your Network
        • Overview of Transit Network Features
          • About Aviatrix Multicloud Transit Network
            • Multicloud Transit Network Design Patterns
          • About Aviatrix ActiveMesh
            • ActiveMesh Design Notes
          • About Aviatrix High-Performance Encryption
            • High Performance Encryption Performance Benchmarks
            • High Performance Encryption for GCP
          • About Aviatrix Gateway High Availability
          • About Aviatrix Gateway Scaling
          • Deploying Azure Gateways and Firewalls using PowerShell
          • About Transit Network Segmentation Overview
          • About Aviatrix Multicloud Transit Architecture for Azure
            • Azure Transit Network Design Patterns
          • About Aviatrix in the China Regions
        • Building a Single-Region Transit Network
        • Building a Multi-Region Transit Network
          • Building Aviatrix Transit Gateway Peering
          • Building Multicloud Transit Gateway Peering over Private Network
          • Building Multicloud Transit Gateway Peering over Public Network
        • Connecting the Transit Network to On-Premise
          • Overview of Connectivity options
          • Overview of Transit Gateway to External Devices
          • Multicloud Transit Integration with External Devices
            • Multicloud Transit to External Devices Workflow
            • Transit Gateway to Cisco Router over the Internet Workflow
            • Transit Gateway to Cisco ASA over the Internet Workflow
            • Transit Gateway to Palo Alto VM-Series Workflow
            • Transit Gateway to FortiGate over the Internet Workflow
            • Transit Gateway to JuniperSRX over the Internet Workflow
            • About External Device Connection Settings
            • Viewing External Connection Details
            • External Device Connection for AWS VGW
            • External Device Connection for Azure VNG
            • Static Policy-Based External Connection
            • Static Route-Based External Connection (ActiveMesh)
            • Static Route-Based External Connection (Mapped)
            • Static Route-Based External Connection (Non-ActiveMesh)
          • Multicloud Transit Integration with AWS VGW Workflow
          • Multicloud Transit Integration with Azure VNG Workflow
          • BGP-Enabled Spoke Gateway to External Devices
          • Multicloud Transit GRE Tunneling in AWS Workflow
          • MultiCloud Transit BGP over LAN in AWS Workflow
          • Multicloud Transit BGP over LAN in Azure Workflow
          • Multicloud Transit BGP over LAN in GCP Workflow
          • Transit Gateway to External Device FAQ
        • Extending Transit Network to Network Edge with Aviatrix Secure Edge
          • Overview of Aviatrix Secure Edge
          • Aviatrix Secure Edge Design Patterns
          • Planning your Aviatrix Secure Edge Deployment
            • Setting up Accounts for Edge Platforms
            • Onboarding Edge Hardware
            • Planning Aviatrix Secure Edge Deployment for On-Premise
            • Planning Aviatrix Secure Edge Deployment for Equinix Network Edge
          • Deploying Aviatrix Secure Edge
            • About Aviatrix Edge Gateway Interfaces and Ports and Protocols
            • Understanding Aviatrix Secure Edge Routing
            • About Edge Gateway Settings
            • Deploying Aviatrix Secure Edge on Equinix Network Edge
            • Deploying Aviatrix Secure Edge in On-Premises
          • Enabling Edge Gateway High Availability
          • Customized SNAT and DNAT on Edge Use Case
          • Implementing Network Segmentation with Aviatrix Edge
          • Enabling Local Internet Breakout at Network Edge
          • Extending Distributed Cloud Firewall to your Network Edge
          • Configuring Transitive Routing with Edge Gateway
          • Configuring Transit Peering Over Public Network with Edge Gateway
          • Creating the Default RBAC Access Account for Edge
        • Connecting Remote Sites to Cloud
          • Overview of Aviatrix Site2Cloud
          • Site2Cloud Configuration Workflow
          • Site2Cloud Configuration with External Devices
            • Aviatrix Gateway to Aviatrix Gateway
            • Aviatrix Gateway to Azure VPN Gateway
            • Aviatrix Gateway to AWS Virtual Private Gateway (VGW)
            • Aviatrix Gateway to Oracle DRG
            • Aviatrix Gateway to Palo Alto Firewall
            • Aviatrix Gateway to Check Point(R77.30)
            • Aviatrix Gateway to Check Point (R80.10)
            • Aviatrix Gateway to Cisco ASA
            • Aviatrix Gateway to Cisco IOS Router
            • Aviatrix Gateway to Sonicwall
            • Aviatrix Gateway to FortiGate
            • Aviatrix Gateway to Juniper SRX
          • Site2Cloud Solution for Encryption over Direct Connect/ExpressRoute
          • Building Site to Site IPsec VPN Connection
          • Site2Cloud Certificate-Based Authentication
          • Troubleshooting IPsec VPN Connection with IKEv2
        • Connecting Networks with Overlapping CIDRs
          • Networks with Overlapping CIDRs Scenarios
          • Configuring Overlapping Networks with Network Mapped IPsec
          • Configuring Overlapping Networks with Customized SNAT and DNAT
            • Connecting On-Prem with Overlapping CIDRs Using Customized SNAT and DNAT on Spoke Gateway
            • Site2Cloud With Customized SNAT
            • Site2Cloud with NAT to fix Overlapping VPC Subnets
            • Site2Cloud to a Public IP Address
            • Connect Networks With Overlapping CIDRs
            • Connect Overlapping VPC/VNet to On-prem
            • Accessing a Virtual IP Address Instance via Aviatrix Transit Network
            • Using Aviatrix Site2Cloud Tunnels to Access VPC Endpoints in Different Regions
        • Overview of UserVPN
          • Aviatrix UserVPN Feature Description
          • Aviatrix UserVPN FAQ
          • Aviatrix User VPN Client
          • UserVPN Gateway Guide
            • Creating a User VPN Default Gateway
            • Creating a Geo VPN Gateway
            • About VPN Gateway Settings
            • Editing VPN Gateways
            • Deleting a VPN Gateway
          • Aviatrix VPN Client (Release Notes)
          • UserVPN SAML Authentication
            • UserVPN with SAML Authentication for Okta IdP
            • UserVPN with SAML Authentication for OneLogin IdP
            • UserVPN with SAML Authentication for Azure AD IdP
            • UserVPN with SAML Authentication for LDAP IdP
            • UserVPN Okta Authentication
            • UserVPN DUO Authentication
        • Enabling Gateway Settings
          • Enabling Spoke Gateway General Settings
          • Enabling Transit Gateway General Settings
          • Enabling Public Subnet Filtering Gateway Settings
          • Enabling Gateway NAT Settings
          • Enabling Gateway BGP Connection Settings
          • Enabling Cloud Service Provider Settings
          • Enabling GCP Global VPC Routing
          • Enabling Gateway Routing Features
          • Using VPC/VNet DNS Server
          • Enabling BGP Route Approval
          • About Gateway States
        • Creating AWS VPC Peering Connection
        • Creating Azure VNET Peering Connection
        • Aviatrix AWS Transit Gateway Orchestrator
          • Overview of AWS Transit Gateway Orchestrator Features
          • Aviatrix AWS Transit Gateway Orchestrator FAQ
          • TGW Design Patterns
          • Migrating a CSR Transit to AWS Transit Gateway (TGW)
          • Migrating a DIY TGW to Aviatrix Managed TGW Deployment
          • Creating TGW Connects
          • AWS Transit Gateway Route Limit Test Validation
        • Performance Improvement with Gateway Scaling
        • AWS Limitations and Solutions
        • Troubleshooting Transit Gateway Connections
        • Extending Your VMware Workloads to Public Cloud
        • Migrating from Classic Aviatrix Encrypted Transit Network to Aviatrix ActiveMesh Transit Network
        • Visualizing Your Network
        • Understanding SmartGroups
          • Creating a SmartGroup
          • Deleting a SmartGroup
          • Modifying a SmartGroup
          • SmartGroups Readme
        • SmartGroups Reference
          • Working with SmartGroups
      • Distributed Cloud Firewall and Security
        • Distributed Cloud Firewall: inspection and enforcement throughout the cloud network
        • About Secured Networking and Security Services
        • Implementing Network Segmentation in an Aviatrix-Managed Network
        • Building a Zero Trust Cloud Network Architecture with Aviatrix
        • Implementing Distributed Cloud Firewall in an Aviatrix-Managed Network
          • Distributed Cloud Firewall Settings
          • Enabling the Distributed Cloud Firewall Feature
            • Enabling the Feature after Changing Licenses
          • Configuring Distributed Cloud Firewall
            • Creating Policies
        • Enabling Security Group Orchestration
        • Planning Your Ingress Traffic Deployment
          • AWS Ingress Firewall Setup Solution
          • Azure Ingress Firewall Setup Solution
          • FireNet Ingress Traffic Inspection
          • Ingress Protection via Aviatrix Transit FireNet with Palo Alto in GCP
        • Implementing Egress in an Aviatrix-Managed Network
          • Using Distributed Cloud Firewall to Configure Egress
          • Egress FQDN Workflow (Legacy)
          • Public Subnet Filtering Gateway for Egress
          • Enabling Local Egress
          • Enabling Transit Egress (centralized)
          • Egress Traffic Overview
          • Egress Monitoring
        • FireNet Deployment Workflow
          • Add FireNet to a Transit Gateway
          • Editing a Transit FireNet
          • Removing Transit FireNet
          • Transit FireNet Settings
          • FireNet Design Patterns
            • Hybrid to On-Prem
            • Hybrid with High Performance Encryption Mode
            • FireNet in Multi-Regions
            • Two Firewall Networks
            • Central Egress in a Multi-Region Deployment
            • Distributed Egress in a Multi-Region Deployment
            • Ingress Protection via Aviatrix Transit FireNet
          • Use Cases for FireNet
          • Launch and Attach a Firewall Using Bootstrap Configuration
          • Create or Modify Connection Policies
            • Azure Spoke Subnet Groups for Attached Spoke Gateways
          • Attach a Spoke to a Transit FireNet
          • Transit FireNet Route Tables
          • Transit FireNet Security Groups
          • Aviatrix Transit FireNet for AWS and Azure
          • AWS Ingress Firewall Setup Solution
        • Firewall Overview
          • Aviatrix FireNet / AWS Transit Gateway Native Deployment Comparison
          • Subscribing to a Firewall Instance (AWS)
          • Launch and Attach a Firewall within a FireNet
          • Disassociating or Deleting or a Firewall Association
          • Manage Firewall Attachments
          • Checking Firewall Health
          • Configure Palo Alto for AWS
          • Configure Palo Alto for Azure
          • Configure Palo Alto for GCP
          • Configure Palo Alto for OCI
          • Configure Panorama Firewall Manager for VM-Series
          • Configure FortiGate for AWS
          • Configure FortiGate for Azure
          • Configure FortiGate for GCP
          • Deploying Check Point CloudGuard
          • Configure Check Point for AWS
          • Configure Check Point for Azure
          • Deploying Azure Gateways and Firewalls using PowerShell
        • Blocking Known Threat IP Traffic using ThreatIQ
          • Blocking Traffic from Countries using GeoBlocking
        • Defining SmartGroups
        • Creating WebGroups
        • Detecting Network Anomalies using Network Behavior Analytics
        • Deploying a Public Subnet Filtering Gateway
      • Monitoring and Troubleshooting
        • How CoPilot Helps You Monitor and Troubleshoot Your Network
        • Monitoring Costs in Your Network
          • Monitoring the Costs of Aviatrix Resources
          • Monitoring the Costs of your Business Units
        • Gaining Visibility into Your Network Topology
          • Creating a Topology Filter
          • Filtering Your Topology by CSP Tags
          • Visibility into Cloud Resources
          • Creating an Inventory Report of Managed Resources
        • Monitoring Traffic Flows
          • Gaining Visibility into Your Traffic Flows
            • Creating a Traffic Flow Filter
          • Monitoring Traffic Flows at the Network Level
          • Monitoring Traffic Flows at the Application Level
          • Monitoring Total Traffic Trends over a Day
          • Monitoring Egress Traffic
          • Monitoring Latencies
            • CoPilot Traffic & Latencies Page Reference
        • Monitoring System Health of Aviatrix-Managed Resources
          • Monitoring Inventory and Status of Managed Resources
          • CoPilot Dashboard Page Reference
          • Viewing Telemetry Data for Managed Resources
          • Monitoring Resource Utilization of Managed Resources
          • Monitoring Gateway Performance and Scaling
          • Monitoring Health of Edge Devices
          • Creating a FlightCheck Report
          • Creating a Resource Utilization Report
          • CoPilot API Authentication
        • Diagnostic Tools
          • Aviatrix CoPilot FAQs
          • Troubleshooting Routing Issues in Your Aviatrix-Managed Network
          • Troubleshooting Application Connectivity Issues
          • Viewing Recent Changes Made to Your Network
          • Viewing Users that made Changes to Your Network
          • Aviatrix Gateway Diagnostics
            • Interpreting Gateway Diagnostic Results
          • Aviatrix Site-to-Cloud Connectivity Diagnostics
          • BGP Connection Diagnostics
          • Aviatrix Controller Diagnostics
        • Notifications (Alerts) about Network Events
          • CoPilot Notifications Page Reference
          • Metrics Monitored for Aviatrix Resources
          • Setting Up Email Channels for Sending Alert Notifications
          • Setting Up Webhook Channels for Sending Alert Notifications
          • Configuring SMTP Service for Controller-Generated Alert Emails
          • Metric Types for Triggering Alerts
          • Metric Threshold Comparators
          • Setting an Evaluation Period for an Alert
          • Setting a Minimum Entity Count for an Alert
          • Configuring Alerts
          • Editing Alert Configurations
          • Deleting Alert Configurations
          • Viewing Alert Notifications
          • Resolving Alerts
          • Pausing Alerts
          • Global Control Plane Health Alert
          • Global Network Health Alert
          • Global Memory Swap Surge Alert
          • Underlay Connection Status Alert
          • Alerts Based on Gateway Status
        • Monitoring for Threats in your Network
        • Monitoring your Network for TLS Vulnerabilities
        • Metrics Monitored for Aviatrix Resources
        • Aviatrix Reports Reference
          • Creating a FlightCheck Report
          • Creating an Inventory Report of Managed Resources
          • Creating a Resource Utilization Report
      • Platform Administration
        • Migrate CoPilot to Appliance V3 (AWS)
          • Troubleshoot the CoPilot Migration
        • Back Up and Restore Your Controller
        • Aviatrix Controller and Gateway Logging
          • Aviatrix Log Formats
          • AWS CloudWatch Integration
        • CoPilot Configuration Settings
          • CoPilot Controller Security Settings
          • CoPilot Certificate Management
          • Controller Certificate Management
          • Controller Security Group Management
        • CoPilot SAML Authentication
        • CoPilot Private Mode Configuration
        • CoPilot Proxy Server Management
        • CoPilot DNS Lookup Server Management
        • IPsec Tunnel Management
        • CoPilot Licensing and Add-On Feature Management
        • CoPilot User Account Administration
        • Configure CoPilot for the Aviatrix Platform
        • CoPilot Disk (Volume) Management
        • CoPilot Tuning and Performance
        • Starting and Stopping CoPilot Services
        • Platform Support Tools
          • CoPilot Support Page Reference
        • Viewing Task Server Overview and History
        • CoPilot Backup and Restore
          • CoPilot Configuration Backup and Restore (AWS Only)
          • CoPilot Index Data Backup
        • Manage Your CoPilot Index
        • Migrating CoPilot Data
        • Deleting a CoPilot Instance
        • Managing Cloud Resources
          • Creating a VPC/VNet using CoPilot
        • CoPilot Support and Troubleshooting
        • Debugging Tools in CoPilot
        • Creating a VPC/VNet using CoPilot
        • Installing Security Patches and Software Patches
          • FIPS 140-2 Module
      • Upgrading Aviatrix
        • Overview of the Aviatrix Controller and Gateways Upgrade
          • Upgrade OpenVPN Users
          • Upgrade HA Gateways in An ActiveMesh Topology
        • Prepare for the Aviatrix Upgrade
          • Upgrade Checklist of the Controller and Gateways Upgrade
          • Pre-upgrade Tasks for Controller and Gateways
        • Procedures for Upgrading Aviatrix
          • Single-Version Upgrade for Controller and Gateways
            • Upgrade your Controller and Gateways via Controller UI
            • Upgrade your Controller and Gateways via CoPilot UI
          • Multiple-Version Upgrade for Controller and Gateways
            • Upgrade your Gateway Image
            • Upgrade your Controller Image
        • Verify Your Upgrade
        • Rollback the Gateway Software
      • CoPilot Release Notes
        • CoPilot Release Notes
        • CoPilot Image Release Notes
  • CoPilot
  • Getting Started

Getting Started

This section includes the following topics:

  • Planning Your CoPilot Deployment

    • CoPilot Platform Requirements

    • CoPilot Deployment Methods

    • CoPilot Simple Deployment

    • CoPilot Fault Tolerant Deployment

  • CoPilot Deployment

    • Deploy CoPilot from your Controller UI (AWS Only)

    • Deploy CoPilot using Terraform

    • Deploy CoPilot from the Marketplace

  • Post CoPilot Deployment Tasks

    • CoPilot Settings to be Enabled in Controller

    • Initial Setup of CoPilot

    • Verify the CoPilot Deployment and the Connectivity with Controller

    • (Optional) Enable CoPilot Add-on Features

    • Set Up SAML Login for CoPilot

  • Logging in to CoPilot

  • Using Aviatrix CoPilot

    • CoPilot Navigation Menu

    • Setting CoPilot UI Preferences

  • Deleting a CoPilot instance

Aviatrix CoPilot Platform Planning Your CoPilot Deployment
Aviatrix
  • Home
  • Docs
  • Support
  • Terms of Use
  • Legal Notice
  • Doc Feedback

Copyright © 2025 Aviatrix Systems, Inc 2901 Tasman Dr #109, Santa Clara, CA 95054