Skip to main content
POST
cURL

Body

application/json
account_name
string
required

Account name created from setup_account_profile.

cloud_type
enum<integer>
required

Cloud type.

Available options:
1,
4,
8,
16,
32,
256,
1024,
2048,
4096,
8192,
131072,
262144,
524288,
1048576
gw_name
string
required

Name of the gateway.

vpc_id
string
required

The vpc id to deploy gateway.

CID
string

The opaque session ID token. Required for 7.2 controllers only.

action
string

The API action to perform. Required for 7.2 controllers only.

add_vpn
enum<string>

Allow VPN access to the container. Default is no. Enter yes if you want to add VPN access to this container.

Available options:
yes,
no
additional_cidrs
string

Additional CIDRs to be pushed to client.

api_hostname
string

DUO API hostname.

auth_method
enum<string>

Authentication method for vpn users.

Available options:
DUO,
google,
okta
auto_advertise_lan_cidrs
enum<string>

Enable/Disable edge gateway auto adverise lan cidrs.

Available options:
disable,
enable
availability_domain
string

Availability domain.

bgp_lan
boolean

BGP over LAN.

bgp_lan_intf_count
integer

BGP over LAN interface count.

bgp_lan_subnet
string

Subnet for BGP over LAN interface.

bgp_lan_vpc
string

VPC for the BGP over LAN interface.

bgp_local_as_num
string

Local BGP ASN.

cloud_init
boolean

Supports cloud-init instead of ISO data.

cluster
string

VPN Cluster name.

create_firewall_gw
boolean

Create an FQDN gateway to use with the given firenet_gw_name.

custom_route_enable_logging
boolean

Enable custom route PBR logging.

custom_route_sub_cidr
string

Specifiy a subnet to attach eth1 intf.

custom_subnet_default_gw
string

Specify the default gateway for eth1 subnet.

customer_managed_keys
string

Customer Master Key.

default_mgmt_interface
string

The host interface to be used as mgmt, by default it is eth2.

designated_gateway
boolean

This gateway is used as Designated routing gateway.

device_id
string

Device UUID of the edge device.

dhcp
boolean

Use DHCP for management interface.

disable_active_standby
boolean

Disables edge gateways active-standby mode.

disable_active_standby_preemptive
boolean

Disables edge gateways active-standby preemptive mode.

dnat_ip_port_list
string

A string of dnat ip port list in json format.

dns_server_ip
string

User provided DNS server IP.

dns_server_ip_secondary
string

User provided secondary DNS server IP.

do_not_delete_iso
boolean

Keep ISO file on the controller.

duo_push_mode
enum<string>

DUO push mode.

Available options:
auto,
selective,
token
edge_gateway
boolean

Create edge gateway (set automatically for Aviatrix cloud type).

eip
string

Reuse existing EIP.

eip_map
string

Public IP mapping for the gateway wan interfaces.

elb_name
string

Create elb with supplied name.

elb_protocol
string

Udp or tcp transportation.

enable_active_standby
boolean

Supports edge gateways in active-standby mode.

enable_active_standby_preemptive
boolean

Supports edge gateways in active-standby preemptive mode.

enable_bgp
enum<string>

Enable BGP routing on spoke.

Available options:
yes,
no
enable_client_cert_auth
boolean

VPN gateway requires clients to have certificates.

enable_client_cert_sharing
boolean

Multiple VPN clients can share certificates.

enable_duplicate_connections
boolean

Allow multiple VPN connections for the same common name.

enable_elb
enum<string>

This gateway will be part of elb group.

Available options:
yes,
no
enable_gwlb
enum<string>

Enable load balancer for gateway group.

Available options:
yes,
no
enable_ipv6
boolean

Enable ipv6 on the gateway.

enable_ldap
boolean

Enable LDAP authentication.

enable_nat
enum<string>

Let gateway do a snat function.

Available options:
yes,
no
enable_otp
boolean

Enable OTP authentication for vpn users.

enc_volume
enum<string>

Encrypt gateway disk volume.

Available options:
yes,
no
exclude_cidr
string

Excluded cidr of spoke vpc for advertising, on transit.

explicit_apply_group_settings
boolean

Derive settings from group after gateway is successfully launched.

fault_domain
string

Fault domain.

firenet
boolean

Create transit gateway for firenet (Azure/GCP).

fqdn_lan_cidr
string

CIDR for FQDN gateway second interface.

global_vpc
boolean

Whether to regional global VPC routing for GCP.

group_uuid
string

Gateway group uuid.

guest_mgmt_interfaces
string

Guest management interfaces.

gw_registration_method
enum<string>

Provide the method to register the gateway.

Available options:
cloud_init,
iso
gw_resource_size
string

Size of gw in terms of CPU and Memory, see edge csp API for choices.

gw_size
string

Cloud instance size of the gateway.

gw_subnet
string

Specify an existing subnet to deploy gateway.

hpe
boolean

Use high performance encryption for this Aviatrix Edge gateway.

image_disk_uri
string

Gateway selective image disk uri.

image_info
string

Json string of selective gateway image info.

image_name
string

Gateway selective image name.

include_cidr
string

Included cidr of spoke vpc for advertising, on spoke.

insane_mode
enum<string>

High performance spoke/transit gateway.

Available options:
yes,
no
insertion_gateway
boolean

Insert a new subnet for the gateway.

integration_key
string

DUO integration key.

interface_mapping
string

User specific interface mapping for the gateway.

interface_mapping_type
enum<string>

pci: Map interfaces by the PCIe IDs. mac: Map interfaces by the mac addresses.

Available options:
custom,
mac,
pci
interfaces
string

Interface configuration.

is_bgp_configured
boolean

Enable/Disable BGP on edge gateway.

is_transit
boolean

Creates Edge as a transit gateway.

json_tags
string

Json string of key:value tags.

lan_default_gateway
string

Default gateway for LAN network.

lan_ifnames
string

Comma separated list LAN host interface names on the edge gateway VM.

lan_ip
string

LAN IP to connect to on premises network.

lan_subnet
string

Subnet for second lan interface.

lan_vpc
string

VPC for the second lan interface.

lb_vpc_id
string

The vpc id of the private link service load balancer.

ldap_additional_req
string

Additional requirements.

ldap_base_dn
string

Base DN for User entries.

ldap_bind_dn
string

Bind DN.

ldap_ca_cert
string

CA cert in PEM format.

ldap_client_cert
string

Client cert in PEM format.

ldap_enable_tls
enum<string>

Enable TLS authentication.

Available options:
yes,
no
ldap_password
string

Bind DN password.

ldap_server
string

LDAP server address.

ldap_user
string

LDAP user.

ldap_user_attr
string

Username attribute.

learned_cidrs_approval
enum<string>

Learned cidrs approval.

Available options:
yes,
no
log_file
string

Full path of the progress log file.

logical_intf_eip_map
string

Public IP mapping for the gateway wan logical interfaces.

logical_wan_interface
string

WAN discovery on logical wan interface.

max_connections
string

Specifiy max number of connections.

mgmt_default_gateway
string

Default gateway for mgmt interface.

mgmt_egress_ip
string

IP cidr for controller to reach gateway.

mgmt_ifnames
string

Comma separated list of Management host interface names on the edge gateway VM.

mgmt_ip
string

Static IP for mgmt interface, in CIDR notation.

mgmt_over_private_network
boolean

Indicate that Gateway to controller traffic is over a private network.

name
string

Name for the Aviatrix Edge gateway instance.

name_servers
string

Nameservers to be pushed to client.

native_vlan
string

Native vlan-id.

no_progress_bar
boolean

Do not show gateway creation progress bar.

okta_token
string

Okta token.

okta_url
string

Okta Url.

okta_username_suffix
string

Okta username suffix.

oob_mgmt_subnet
string

Secondary subnet for oob mgmt intf.

ph2_encryption_policy
enum<string>

Phase 2 encryption policy for the gateway.

Available options:
default,
strong
ph2_pfs_policy
enum<string>

Phase 2 PFS policy for the gateway.

Available options:
disable,
enable
phase2_dh
string

Phase 2 PFS policy for the gateway.

phase2_encryption
string

Phase 2 encryption policy for the gateway.

private_channel
boolean

Enables private mode. Spoke/Tranist use private ip to communicate.

private_network
boolean

Deploy gateway without public IP.

private_subnet_egress_target
string

Egress target ID (e.g. nat-xxx, tgw-xxx) for the gateway route table. Required for HPE gateways with private_network.

public_dns_server
string

Public DNS server.

regular_gateway
boolean

When specified indicates regular gateway.

saml_gw
boolean

Enable SAML based VPN for Gateway.

search_domains
string

Search domains to be pushed to client.

secret_key
string

DUO secret key.

site_id
string

Optional site id.

split_tunnel
enum<string>

Split tunnel only encrypts traffic to specified destination.

Available options:
yes,
no
spot_instance
boolean

Launch spot instance.

spot_price
string

Maximum spot instance price.

storage
string

AzureARM/OCI image storage.

tag
string

Tag key:value pair comma separated list.

transit
boolean

When specified indicates transit gateway, otherwise spoke gateway.

transit_peering_as_onprem_backup
enum<string>

Enable or disable transit peering as onprem backup.

Available options:
disable,
enable
vlan
string

VLAN configuration.

vpc_region
string

The region of an existing vpc.

vpn_cidr
string

CIDR block reserved for VPN clients.

vpn_user_email_domain
string

Valid email domain names for vpn users.

wan_default_gateway
string

Default gateway for the WAN interface.

wan_discovery_ip
string

Edit wan discovery public ip.

wan_ifnames
string

Comma separated list of host WAN interfacess on the edge gateway VM.

wan_interface
string

WAN discovery interface.

wan_ip
string

WAN IP to connect to transit gateways.

zone
string

Gateway Zone.

Response

General v2 API response schema.

A generic API response container for v2 style APIs.

errortype
string

Error type if the API failed.

reason
string

Failure reason if the API failed.

results

API response data

return
boolean

Whether the API returned successfully