diff --git a/HowTos/Aviatrix_Account_Azure.rst b/HowTos/Aviatrix_Account_Azure.rst index f337a0990..b150388e0 100644 --- a/HowTos/Aviatrix_Account_Azure.rst +++ b/HowTos/Aviatrix_Account_Azure.rst @@ -167,7 +167,6 @@ Prerequisites: - You must already have a Microsoft Azure China account and Aviatrix Controller in AWS China to deploy an Aviatrix Gateway in the Azure China Cloud. -- If you have not created a storage account in your Microsoft Azure cloud, create a storage account first. 1. Create the Aviatrix Controller in your AWS China Cloud. Go to Onboarding and select Azure China. @@ -177,9 +176,7 @@ Prerequisites: 4. Create the Primary Access Account. -5. Download the Aviatrix gateway image to your Microsoft Azure China storage account in a specified region. If the storage account does not exist, go to Azure China portal to create one first. Note: The download may take up to 20 minutes due to Azure infrastructure limitations. - -6. Deploy Aviatrix gateway in Gateway page or Multi-Cloud Transit Solution page. +6. Deploy Aviatrix gateway from the Gateway page in the Aviatrix Controller or the Multi-Cloud Transit Solution page. For more information, see “What is a China ICP License?” diff --git a/HowTos/CloudN_workflow.rst b/HowTos/CloudN_workflow.rst index b017a1473..ef721e791 100644 --- a/HowTos/CloudN_workflow.rst +++ b/HowTos/CloudN_workflow.rst @@ -227,7 +227,11 @@ Step 2.6 Register with Aviatrix Controller FQDN Name .. important:: - It is highly recommended that a FQDN name is used instead of an IP address for enhanced security and controller HA. + It is highly recommended to register CloudN with Aviatrix Controller’s FQDN name instead of its IP address for allowing Controller HA operation (allows the controller to be assigned to a different IP address). + + When your Aviatrix Controller's FQDN is mapped to a private IP address, make sure that CloudN’s MGMT primary DNS server or secondary DNS server can resolve the FQDN to its private IP address. + + Registering CloudN to Aviatrix Controller via private networks is not a fully supported scenario; please discuss this with the Aviatrix team during the planning phase before you finalize the design for the Managed CloudN deployment. - Enter Aviatrix Controller Username/Password with an admin user credential (any users in admin RBAC Groups) diff --git a/HowTos/SAML_Integration_Azure_AD_IdP.rst b/HowTos/SAML_Integration_Azure_AD_IdP.rst index 468022dc5..09f9e859e 100644 --- a/HowTos/SAML_Integration_Azure_AD_IdP.rst +++ b/HowTos/SAML_Integration_Azure_AD_IdP.rst @@ -125,7 +125,7 @@ Click **Single sign-on** below **Manage** | Relay State | (leave blank) | +----------------------------+-----------------------------------------+ - |imageSAMLSettings| + The links for the SAML Identifier, Reply URL, and Sign on URL should point to the Application Gateway domain instead of the Aviatrix controller. **User Attributes** diff --git a/HowTos/UCC_Release_Notes.rst b/HowTos/UCC_Release_Notes.rst index 6926f97e6..a577987bf 100644 --- a/HowTos/UCC_Release_Notes.rst +++ b/HowTos/UCC_Release_Notes.rst @@ -2,6 +2,7 @@ Release Notes ======================================= +======= 6.5.2898 (01/11/2022) ===================== diff --git a/HowTos/aviatrix_china_overview.rst b/HowTos/aviatrix_china_overview.rst index 6ed83205b..d69e1e470 100644 --- a/HowTos/aviatrix_china_overview.rst +++ b/HowTos/aviatrix_china_overview.rst @@ -46,6 +46,8 @@ What Features Are Supported in Which China Region Cloud? +------------------------------------------------------------------------+---------------+-----------------+---------------------------+ | Firewall Network | No | No | No | +------------------------------------------------------------------------+---------------+-----------------+---------------------------+ +| Firenet | No | Yes | No | ++------------------------------------------------------------------------+---------------+-----------------+---------------------------+ | Insane Mode Encryption | No | No | No | +------------------------------------------------------------------------+---------------+-----------------+---------------------------+ | Managed CloudN | No | No | No | diff --git a/HowTos/azure_saml_auth_vpn_access.rst b/HowTos/azure_saml_auth_vpn_access.rst new file mode 100644 index 000000000..151fa57d5 --- /dev/null +++ b/HowTos/azure_saml_auth_vpn_access.rst @@ -0,0 +1,90 @@ +====================================================================== +Azure Controller Security for SAML Based Authentication VPN Deployment +====================================================================== + +The best security practice for the Aviatrix Controller is to prevent the controller from being widely accessible from the internet. Access on TCP port 443 should be limited to: + +- The range of management IPs coming from the enterprise or the datacenter. +- Ingress and egress access for basic communications and keep-alive signals from each gateway. + +The exception to this best practice is when the Aviatrix Controller is used for Security Assertion Markup Language (SAML) based authentication user VPN access. In this case, the VPN user first contacts the Aviatrix Controller which then redirects user browser traffic to an Identity Provider (IdP) system, Okta for example. The initial VPN authentication traffic runs on Aviatrix Controller TCP port 443 for VPN users located off-site, so controller TCP port 443 needs to be open to all which may cause security concerns. + +You must configure Aviatrix SAML authentication for your user VPN access. The SAML authentication should be configured through the Azure Application Gateway (AppGW) so the gateway access to the Aviatrix Controller is authenticated through the AppGW. The URLs generated use the AppGW domain instead of controller domain. VPN users should not access the controller directly, they should access the controller through the AppGW where access rules are enforced. + +In order prevent the controller from being widely accessible and allow SAML authentication user VPN access, please follow the instructions in this section to secure your controller when Security Assertion Markup Language (SAML) based authentication is being used. + +Alternative Use Cases for SAML Based User Authentication +======================================================== + +The Azure Application Gateway is a generic, workload agnostic reverse proxy and load balancer that includes a web application firewall (WAF). + +- The service consists of Azure-managed VMs running Nginx in a VNET. Unless restricted, these VMs have access to the public internet, the VNET address space, and anything else a VM in that VNET can talk to. +- In addition to VMs, backends can be IP addresses. +- The Application Gateway is also an Ingress Controller option for the Azure Kubernetes Service. + +From an Application Gateway perspective, the Aviatrix Controller is just another workload. The configurations in this section can be applied to any other HTTP or HTTPS workload. For example, you can use the Azure Application Gateway to: + +- Protect an application running in an on-prem datacenter. +- Protect a hosted PaaS web application injected into the VM. +- Add HTTPS support to an older application that can only run HTTP. +- Restrict or redirect URL patterns within an application. + +Prerequisites +============= + +You need to understand how to configure OpenVPN SAML authentication. For more information, see `OpenVPN with SAML Authentication `_. + +Securing the Aviatrix Controller for SAML Based Authentication Behind an Azure Application Gateway +================================================================================================== + +To secure your controller when Security Assertion Markup Language (SAML) based authentication is being used: + +1. Create valid SSL certificates for the Aviatrix Controller and Azure Application Gateway virtual machine. Use any valid SSL certificate generation application. +2. On the Azure portal, create a subnet for the Azure Application Gateway. Create the subnet in your Aviatrix Controller’s VNET for the Azure Application Gateway. The Azure Application Gateway requires its own subnet. +3. Apply the certificates to the Controller. + +- On the Aviatrix Controller, go to the Controller Settings > Security > Advanced > Controller Certificate Import Methods. The preferred method is to select “Import Certificate with Key”, you can also select “Generate CSR and Import Certificate”. +- Import the certificate files. +- After you click OK, the Aviatrix Controller browser refreshes using the new certificate. Verify the correct certificates are in use with your favorite SSL validation site. + +For more information, see `Controller Certificate Management `_. + +4. On the Aviatrix Controller, go to Settings > Controller > Access Security > Security. Enable the Controller Primary Access Account on the Controller Security Group Management card to only allow access to the Controller Public IP from Aviatrix Gateways. In the Azure Portal, the Network Security Group (NSG) assigned to the Controller is usually -nsg. +5. On the Azure portal, create a new Azure Application Gateway: + +- Specify the Basic details. +- Configure Frontends and create a Public IP. +- Create a Backend pool. Specify the NIC of the controller virtual machine as the target. +- Add a Routing Rule. Create a rule Name and enter the required values on the Listener tab. +- Enter the required values on the Backend targets tab. The Backend Target is the backend pool created earlier. +- Click Add new and configure the HTTP Settings. + +A. Set the Request timeout value to 3600. Otherwise, timeouts on legitimate requests may occur. +B. Override the hostname with the FQDN chosen for the backend certificate. + +6. On the Azure portal, modify the associated Azure Network Security Group to allow the Azure Application Gateway subnet. +7. On the Azure portal, enable monitoring of the Application Gateway. Add a diagnostic setting and configure the desired logging settings. +8. On the Azure portal, disable rules for the Application Gateway to prevent errors with onboarding accounts. + +- Enable advanced rule configuration. +- Disable rules 200004, 931130, and 942430. + +9. On the Azure portal, enable URL Rewrite to avoid Cross-Origin Resource Sharing (CORS) errors. + +- Create a Rewrite set. +- Name the Rewrite set and assign it to the Aviatrix Controller routing rule. +- Rename the rule to something descriptive. +- On the Azure portal, enable URL Rewrite to avoid Cross-Origin Resource Sharing (CORS) errors. + +10. On the Azure portal, put the Aviatrix Controller behind the Application which includes a web application firewall (WAF). The WAF will block requests with special entity names. Do not create entity name with special strings because the API will be blocked with a 403 error. +11. Create SAML endpoint. For more information see OpenVPN with SAML Authentication https://docs.aviatrix.com/HowTos/VPN_SAML.html. +12. Create the Azure Application Gateway. +13. onfigure the Azure Application Gateway. + +.. Note:: For the HTTP Settings, when using the "Use well known CA certificate" option you may see a message about the root certificate of the server certificate used by the backend not matching the trusted root certificate added to the application gateway. To resolve this issue, use the fullchain certificate when importing the server certificate into the controller. +.. + +.. Note:: While authenticating the VPN user with an IdP and when sending the SAML response to the controller, you may see an error message about an invalid SAML response and the subject or username 'NoneType'. To resolve this issue, disable "override hostname" in the application gateway's controller-settings because the controller code checks the metadata and controller URL. +.. + + diff --git a/HowTos/bgp_transitive_instructions.rst b/HowTos/bgp_transitive_instructions.rst index 91811c940..da6261ad5 100644 --- a/HowTos/bgp_transitive_instructions.rst +++ b/HowTos/bgp_transitive_instructions.rst @@ -8,7 +8,7 @@ Transit Network with BGP Setup Instructions .. Important:: - this document is obsolete with 3.1 release. Follow `Transit Network workflow instructions `__ to setup a Transit Network. + This document is obsolete for release 3.1 and later releases. Follow `Transit Network workflow instructions `__ to setup a Transit Network. Introduction ============= diff --git a/HowTos/copilot_faq.rst b/HowTos/copilot_faq.rst index 15272cc08..34b857296 100644 --- a/HowTos/copilot_faq.rst +++ b/HowTos/copilot_faq.rst @@ -105,6 +105,12 @@ Can we provide bandwidth details of links/tunnels ? =============================================================================== If you can specify source and destination for the two endpoints of the path, i.e gateways, you will be able to obtain this information from FlowIQ by using filters. + +Why do I get an error Failed to fetch Topology when I open the Topology page? +=============================================================================== + +If you get the error **Failed to fetch Topology data** when opening the Topology page, CoPilot was unable to access the data it needs for topology. If the issue persists, Contact Aviatrix Support. + How I can get my additional questions answered ? =============================================================================== diff --git a/HowTos/copilot_reference_guide.rst b/HowTos/copilot_reference_guide.rst index 181009b30..333694e11 100644 --- a/HowTos/copilot_reference_guide.rst +++ b/HowTos/copilot_reference_guide.rst @@ -117,6 +117,9 @@ Objects on the topology maps support drag and drop. You can click, drag and drop By default topology objects are organized using physics engines. This menu allows you to configure physical gravity settings that manage the placement of objects. You can adjust different parameters, or turn the physics off + completely for complete control over placement of the objects. + +======= completely for complete control over placement of the objects. @@ -165,6 +168,7 @@ This section describes the physics options that control how objects move in the | | moving after having been dragged. | +-------------------------+------------------------------------------------------------------------------------+ + Performing diagnostics from Topology ------------------------------------- @@ -176,6 +180,23 @@ To perform diagnostics from Topology (from an Aviatrix Gateway): 2. Click the DIAG button. +3. Perform any of the following diagnostic tasks for the gateway: + + a. PING: Run pings directly from the gateway to outside of the Aviatrix managed network or to any resource inside the network. + + b. TRACEROUTE: Run trace route. + + c. Test Connectivity: Test the connectivity of the gateway to a specified host running on a specified TCP or UDP port. + + d. ACTIVE SESSIONS: View sessions that are active on the selected gateway. You can filter active sessions by search criteria. For example, a search on a specific port to see if the gateway has an action session on that port. + + e. INTERFACE STATS: View interface statistics about the gateway. The number of interfaces or tunnels associated with the gateway is displayed. Click on the name of an interface or tunnel to see its statistical information. +======= + +1. In Topology, click on an Aviatrix Gateway in the topology map to select it. + +2. Click the DIAG button. + 3. Perform any of the following diagnostic tasks for the gateway: a. PING: Run pings directly from the gateway to outside of the Aviatrix managed network or to any resource inside the network. @@ -318,6 +339,7 @@ Properties of the time series panel include: The View icon indicates a change set at that point in time. Click on a View control to load a change set; this populates the network constructs associated with the changes in the topology map and displays the details for their changes in the changes details pane. The constructs associated with the changes are circled in the map. + Working with FlowIQ =================== diff --git a/HowTos/copilot_release_notes.rst b/HowTos/copilot_release_notes.rst index 83420da32..1a5091505 100644 --- a/HowTos/copilot_release_notes.rst +++ b/HowTos/copilot_release_notes.rst @@ -7,6 +7,7 @@ Aviatrix CoPilot Release Notes ============================================================ +======= CoPilot Release 1.5.0 (1/12/2022) --------------------------------- diff --git a/HowTos/gateway.rst b/HowTos/gateway.rst index 857c8c0ff..83e51d75a 100644 --- a/HowTos/gateway.rst +++ b/HowTos/gateway.rst @@ -44,16 +44,6 @@ AWS Performance numbers: +============================+=================================================+ | T2 series | Not guaranteed; it can burst up to 130Mbps | +----------------------------+-------------------------------------------------+ -| M3 series | 300 - 500Mbps | -+----------------------------+-------------------------------------------------+ -| m4.xlarge, c4.xlarge | approximately 500Mbps | -+----------------------------+-------------------------------------------------+ -| c3.2xlarge, m4.2xlarge | approximately 1Gbps | -+----------------------------+-------------------------------------------------+ -| c3.4xlarge | approximately 1.2Gbps | -+----------------------------+-------------------------------------------------+ -| c4.2xlarge | 1.2Gbps - 1.5Gbps | -+----------------------------+-------------------------------------------------+ | c5.2xlarge, c5.4xlarge | 2Gbps - 2.5Gbps | +----------------------------+-------------------------------------------------+ | c5n.4xlarge | 25Gbps (with InsaneMode) | diff --git a/HowTos/spokegw_external_media/External-Device-DX.png b/HowTos/spokegw_external_media/External-Device-DX.png new file mode 100644 index 000000000..5da7d1218 Binary files /dev/null and b/HowTos/spokegw_external_media/External-Device-DX.png differ diff --git a/HowTos/spokegw_external_media/External-Device-Internet.png b/HowTos/spokegw_external_media/External-Device-Internet.png new file mode 100644 index 000000000..15f60a4fa Binary files /dev/null and b/HowTos/spokegw_external_media/External-Device-Internet.png differ diff --git a/HowTos/spokegw_external_media/download_config_external.png b/HowTos/spokegw_external_media/download_config_external.png new file mode 100644 index 000000000..3e0981cab Binary files /dev/null and b/HowTos/spokegw_external_media/download_config_external.png differ diff --git a/HowTos/spokegw_external_media/spokegw_external_custom_adv_cidrs.png b/HowTos/spokegw_external_media/spokegw_external_custom_adv_cidrs.png new file mode 100644 index 000000000..32d01438e Binary files /dev/null and b/HowTos/spokegw_external_media/spokegw_external_custom_adv_cidrs.png differ diff --git a/HowTos/spokegw_external_media/spokegw_external_ex_arch.png b/HowTos/spokegw_external_media/spokegw_external_ex_arch.png new file mode 100644 index 000000000..675ec976a Binary files /dev/null and b/HowTos/spokegw_external_media/spokegw_external_ex_arch.png differ diff --git a/HowTos/spokegw_external_media/spokegw_external_saas_sol.png b/HowTos/spokegw_external_media/spokegw_external_saas_sol.png new file mode 100644 index 000000000..ea2f2e5d3 Binary files /dev/null and b/HowTos/spokegw_external_media/spokegw_external_saas_sol.png differ diff --git a/HowTos/spokegw_external_media/transitgw_bgp.png b/HowTos/spokegw_external_media/transitgw_bgp.png new file mode 100644 index 000000000..90780182e Binary files /dev/null and b/HowTos/spokegw_external_media/transitgw_bgp.png differ diff --git a/HowTos/spokegw_external_media/transitgw_bgp_dx.png b/HowTos/spokegw_external_media/transitgw_bgp_dx.png new file mode 100644 index 000000000..a7f7b0525 Binary files /dev/null and b/HowTos/spokegw_external_media/transitgw_bgp_dx.png differ diff --git a/HowTos/spokegw_external_media/transitgw_dx.png b/HowTos/spokegw_external_media/transitgw_dx.png new file mode 100644 index 000000000..07c9b9f10 Binary files /dev/null and b/HowTos/spokegw_external_media/transitgw_dx.png differ diff --git a/HowTos/spokegw_external_media/transitgw_internet.png b/HowTos/spokegw_external_media/transitgw_internet.png new file mode 100644 index 000000000..f4f107a7d Binary files /dev/null and b/HowTos/spokegw_external_media/transitgw_internet.png differ diff --git a/HowTos/spokegw_external_media/transitgw_phase1_dx.png b/HowTos/spokegw_external_media/transitgw_phase1_dx.png new file mode 100644 index 000000000..8c56ee773 Binary files /dev/null and b/HowTos/spokegw_external_media/transitgw_phase1_dx.png differ diff --git a/HowTos/spokegw_external_media/transitgw_phase2_dx.png b/HowTos/spokegw_external_media/transitgw_phase2_dx.png new file mode 100644 index 000000000..371b389c8 Binary files /dev/null and b/HowTos/spokegw_external_media/transitgw_phase2_dx.png differ diff --git a/HowTos/spokegw_external_media/transitgw_phrase1.png b/HowTos/spokegw_external_media/transitgw_phrase1.png new file mode 100644 index 000000000..c728f27e2 Binary files /dev/null and b/HowTos/spokegw_external_media/transitgw_phrase1.png differ diff --git a/HowTos/spokegw_external_media/transitgw_phrase2.png b/HowTos/spokegw_external_media/transitgw_phrase2.png new file mode 100644 index 000000000..03c380b7e Binary files /dev/null and b/HowTos/spokegw_external_media/transitgw_phrase2.png differ diff --git a/HowTos/spokegw_external_media/transitgw_private_aws.png b/HowTos/spokegw_external_media/transitgw_private_aws.png new file mode 100644 index 000000000..b9715cc58 Binary files /dev/null and b/HowTos/spokegw_external_media/transitgw_private_aws.png differ diff --git a/HowTos/spokegw_external_media/transitgw_private_azure.png b/HowTos/spokegw_external_media/transitgw_private_azure.png new file mode 100644 index 000000000..8ff92ff94 Binary files /dev/null and b/HowTos/spokegw_external_media/transitgw_private_azure.png differ diff --git a/HowTos/spokegw_external_media/transitgw_tunnel _dx.png b/HowTos/spokegw_external_media/transitgw_tunnel _dx.png new file mode 100644 index 000000000..894d453bc Binary files /dev/null and b/HowTos/spokegw_external_media/transitgw_tunnel _dx.png differ diff --git a/HowTos/spokegw_external_media/transitgw_tunnel.png b/HowTos/spokegw_external_media/transitgw_tunnel.png new file mode 100644 index 000000000..39ece8a50 Binary files /dev/null and b/HowTos/spokegw_external_media/transitgw_tunnel.png differ diff --git a/HowTos/spokegw_external_media/transitgw_tunnel_dx.png b/HowTos/spokegw_external_media/transitgw_tunnel_dx.png new file mode 100644 index 000000000..894d453bc Binary files /dev/null and b/HowTos/spokegw_external_media/transitgw_tunnel_dx.png differ diff --git a/HowTos/tgwconnect.rst b/HowTos/tgwconnect.rst new file mode 100644 index 000000000..7804641a9 --- /dev/null +++ b/HowTos/tgwconnect.rst @@ -0,0 +1,57 @@ +.. meta:: + :description: AWS TGW Connect over Direct Connect + :keywords: AWS TGW Connect,DX + + +============================================================ +AWS TGW Connect over Direct Connect +============================================================ + + +Overview for AWS TGW Connect over Direct Connect +================================================ + +Amazon Web Services (AWS) enables AWS customers to integrate their Software Defined Wide Area Network (SD-WAN) devices with AWS Transit Gateway and AWS Direct Connect so they can use their existing SD-WAN devices to connect their on-premises networks to an AWS Transit Gateway. Refer to the following AWS articles for information about the attachments types involved (Transit Gateway Connect attachment and Transit Gateway Connect peer): + +https://aws.amazon.com/blogs/networking-and-content-delivery/simplify-sd-wan-connectivity-with-aws-transit-gateway-connect/ + +https://aws.amazon.com/blogs/networking-and-content-delivery/integrate-sd-wan-devices-with-aws-transit-gateway-and-aws-direct-connect/ + +In support of this, Aviatrix enables you to create one or multiple Transit Gateway Connect attachments over Direct Connect. You can also create Transit Gateway Connect peer attachments. For instructions, see Enable AWS TGW connect over Direct Connect. + +Enable AWS TGW Connect over Direct Connect +=========================================== + +To enable AWS TGW Connect over Direct Connect: + +1. (On AWS) Set up Direct Connect Gateway and the Transit virtual interface. +2. (In Aviatrix Controller) Edit the TGW CIDR blocks. Go to the TGW Orchestrator > List > TGW tab. Select the gateway and edit its CIDR in the Edit TGW CIDR dialog. + - Maximum number of CIDR blocks is 5. + - The CIDR block must be the same as Direct Connect allowed prefix (e.g., 20.0.0.0/24). +3. (In Aviatrix Controller) Build TGW Direct Connect attachment with allowed prefix (e.g., 20.0.0.0/24). +4. (In Aviatrix Controller) Build TGW Connect attachment over AWS Direct Connect. In the TGW Orchestrator, in the step for Setup TGW Connect, select either the VPC attachment or the AWS Direct Connect attachment. You can build multiple TGW Connect attachments with the same transport Direct Connect attachment. +5. (In Aviatrix Controller) Build TGW Connect peer with GRE configuration. A connect peer is a GRE tunnel. The TGW Connect attachment supports up to four GRE tunnels (connect peers). Below is the information you specify (TGW Orchestrator > List > Attachments tab > Create Connect PeerWS) to create the TGW Connect peer. For the desciption of each parameter, refer to the AWS article: https://aws.amazon.com/blogs/networking-and-content-delivery/integrate-sd-wan-devices-with-aws-transit-gateway-and-aws-direct-connect/. + + Enter the information in Create Connect Peer: + + - Maximum number of TGW Connect peer: 4 + - AWS Transit Gateway GRE address: + - Peer GRE address: + - BGP Inside CIDR blocks: + + The BGP addresses must be unique across all tunnels in a TGW. IPv6 is not supported. The following CIDR blocks are reserved and cannot be used: + + 169.254.0.0/29, 169.254.1.0/29, 169.254.2.0/29, 169.254.3.0/29, 169.254.4.0/29, 169.254.5.0/29, 169.254.169.252/29 + + - Peer ASN: +6. (On your third-party branch appliances) Complete the Connect peer configuration (GRE tunnel and BGP peering configuration). + +If you have the same prefix propagated into your TGW route table coming from VPN, Direct Connect, and Transit Gateway Connect attachments, AWS evaluates the best path in the following order: + +Priority 1 – Direct Connect Gateway attachment + +Priority 2 – Transit Gateway Connect attachment + +Priority 3 – VPN attachment + +TGW Connect attachment over AWS Direct Connect diff --git a/StartUpGuides/google-aviatrix-cloud-controller-startup-guide.rst b/StartUpGuides/google-aviatrix-cloud-controller-startup-guide.rst index 429db001e..975b3cfc7 100644 --- a/StartUpGuides/google-aviatrix-cloud-controller-startup-guide.rst +++ b/StartUpGuides/google-aviatrix-cloud-controller-startup-guide.rst @@ -101,7 +101,7 @@ At the top screen, click “[+] CREATE IMAGE”, make sure to: **aviatrix300/aviatrix-cloud-services-gateway-032020-byol.tar.gz** -- Click create, as shown below. +- Click **Create**. |image1| @@ -130,12 +130,12 @@ At the GCloud console, - Select “Read Write” for Compute. -- At Firewall, click “Allow HTTPS Traffic”, as shown below. +.. Important:: -- Click Create. + Do not check the **Firewall** box to **Allow HTTPS Traffic**. Aviatrix reccomends you improve security by removing any 0.0.0.0 entries on port 443 not allowing the Aviatrix Controller to the world. + +- Click **Create**. - |image2| - Option #2: Deploy Aviatrix Controller in GCP Marketplace (Preview mode) ======================================================================= @@ -154,11 +154,11 @@ Option #2: Deploy Aviatrix Controller in GCP Marketplace (Preview mode) |gcp_controller_gcp_marketplace_02| -- HTTPS with port 443 from anywhere user access (User Interface) +.. Important:: - |gcp_controller_gcp_marketplace_03| - -- Click the button "DEPLOY" + Do not check the **Firewall** box to **Allow HTTPS Traffic**. Aviatrix reccomends you improve security by removing any 0.0.0.0 entries on port 443 not allowing the Aviatrix Controller to the world. + +- Click **DEPLOY**. Access the Aviatrix Controller ============================== diff --git a/index.rst b/index.rst index 8f109e28a..205014e48 100644 --- a/index.rst +++ b/index.rst @@ -94,6 +94,7 @@ While all content is searchable, the site is organized into the following sectio HowTos/transitvpc_faq HowTos/transitvpc_workflow HowTos/transitgw_external + HowTos/spokegw_external HowTos/transit_approval HowTos/transit_advanced HowTos/transitvpc_designs @@ -132,6 +133,7 @@ While all content is searchable, the site is organized into the following sectio HowTos/transitgw_external HowTos/transitvpc_workflow HowTos/transitvpc_design + HowTos/tgwconnect .. _Firewall Network: @@ -371,6 +373,7 @@ While all content is searchable, the site is organized into the following sectio StartUpGuides/aws_manual_startup_guide HowTos/site_to_site_vpn HowTos/controller_security_for_SAML + HowTos/azure_saml_auth_vpn_access HowTos/simpletransit HowTos/s2c_vgw_snat HowTos/s2c_overlapping_subnets