Running a GKE on top of an Aviatrix Secure Cloud Network – Part 2

Multi Cluster Systems (MCS) Aviatrix Overview Aviatrix is a cloud network platform that brings multi-cloud networking, security, and operational visibility capabilities that go beyond what any cloud service provider offers. Aviatrix software leverages AWS, Azure, GCP and Oracle Cloud APIs to interact with and directly program native cloud networking constructs, abstracting the unique complexities of each cloud to form one network data plane, and adds advanced networking, security and operational features enterprises require. FireNet Aviatrix Transit FireNet allows the deployment of 3rd party firewalls onto the Aviatrix transit architecture. Transit FireNet works the same way as the Firewall Network where … Continue reading Running a GKE on top of an Aviatrix Secure Cloud Network – Part 2

Aviatrix Gateway auto scale v1 is here!

Aviatrix is evolving to address the challenge of deploy, secure, and operate a secure multi cloud networking. As it advances to fill the gaps it still requires certain knowledge of the environment like determine the size of the gateways instances: an over provisioned gateway can cost more than necessary but on the other side an under provisioned gateway can impact the performance and availability of applications. CoPilot 1.10 released in May brought the capability to create policies that based on the telemetry allows to scale the managed resources up or down. Later the feature will support to scale the resources … Continue reading Aviatrix Gateway auto scale v1 is here!

FortiNet SD-WAN Integration with Aviatrix

BGP to LAN allows an Aviatrix multi-cloud network to communicate with network virtualization appliances (NVAs) without running tunneling protocols. One case is to interoperate with third-party SD-WAN appliances. https://community.aviatrix.com/t/h7htvvc/need-of-conventional-bgp-support-in-the-cloud Constraints LAN interfaces for Aviatrix Transit Primary and third-party cloud instance must be in the different VNets One BGP over LAN connection per gateway is supported. Aviatrix software version 6.8 will not require a dedicated vnet for sd-wan appliances Configuration Once the vnet is created, using the Native Peering, I’ll peer the new vnet with the transit vnet for control and data plane reachability: When the peering is established we can … Continue reading FortiNet SD-WAN Integration with Aviatrix

Deploying an Aviatrix FireNet on Azure with Fortinet FortiGate

Aviatrix Transit FireNet allows the deployment of 3rd party firewalls onto the Aviatrix transit architecture. Transit FireNet works the same way as the Firewall Network where traffic in and out of the specified Spoke is forwarded to the firewall instances for inspection or policy application. FireNet Design The diagram below shows the Aviatrix Firenet design for Azure. When a transit gateway is deployed with the firenet option checked, the Aviatrix controller will: create subnets create UDRs create an internal NLB configure the internal NLB (front end, back-end, healtch check) Aviatrix deploys and configures the Internal Load Balancers for a Firenet. … Continue reading Deploying an Aviatrix FireNet on Azure with Fortinet FortiGate

Deploying Aviatrix Controller and CoPilot on GCP behind Cloud Armor

Quick Overview The Aviatrix Cloud Network Platform consists of a centralized controller that is multi-cloud aware, intelligent cloud routers called gateways, and CoPilot, a day 2 platform providing visibility and analytics. An example of an Aviatrix managed deployment is provided below. The diagram below depicts the design I’m going to detail in the next sections: Aviatrix controller is exposed as a backend service through a external HTTPs classic load balancer the Load Balancer also protects the Controller against L2/L3/L4 exhaustion attacks Cloud DNS provides name resolution to the front end IPs of the load balancer Google Certificate Authority is used … Continue reading Deploying Aviatrix Controller and CoPilot on GCP behind Cloud Armor

Connecting Cisco ACI to Aviatrix

Cisco ACI Overview It is a Software Defined Network (SDN) solution from Cisco for Data Centers. ACI fabric consists of discrete components connected in a spine and leaf switch topology that it is provisioned and managed as a single entity: Application Policy Infrastructure Controller (APIC): The APIC is the point of configuration for policies and the place where statistics are archived and processed to provide visibility, telemetry, and application health information and enable overall management of the fabric. The controller is a physical appliance based on a Cisco UCS rack server with two interfaces for connectivity to the leaf switches. … Continue reading Connecting Cisco ACI to Aviatrix