Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 1 addition & 4 deletions HowTos/Aviatrix_Account_Azure.rst
Original file line number Diff line number Diff line change
Expand Up @@ -167,7 +167,6 @@ Prerequisites:

- You must already have a Microsoft Azure China account and Aviatrix Controller in AWS China to deploy an Aviatrix Gateway in the Azure China Cloud.

- If you have not created a storage account in your Microsoft Azure cloud, create a storage account first.

1. Create the Aviatrix Controller in your AWS China Cloud. Go to Onboarding and select Azure China.

Expand All @@ -177,9 +176,7 @@ Prerequisites:

4. Create the Primary Access Account.

5. Download the Aviatrix gateway image to your Microsoft Azure China storage account in a specified region. If the storage account does not exist, go to Azure China portal to create one first. Note: The download may take up to 20 minutes due to Azure infrastructure limitations.

6. Deploy Aviatrix gateway in Gateway page or Multi-Cloud Transit Solution page.
6. Deploy Aviatrix gateway from the Gateway page in the Aviatrix Controller or the Multi-Cloud Transit Solution page.

For more information, see “What is a China ICP License?”

Expand Down
6 changes: 5 additions & 1 deletion HowTos/CloudN_workflow.rst
Original file line number Diff line number Diff line change
Expand Up @@ -227,7 +227,11 @@ Step 2.6 Register with Aviatrix Controller FQDN Name

.. important::

It is highly recommended that a FQDN name is used instead of an IP address for enhanced security and controller HA.
It is highly recommended to register CloudN with Aviatrix Controller’s FQDN name instead of its IP address for allowing Controller HA operation (allows the controller to be assigned to a different IP address).

When your Aviatrix Controller's FQDN is mapped to a private IP address, make sure that CloudN’s MGMT primary DNS server or secondary DNS server can resolve the FQDN to its private IP address.

Registering CloudN to Aviatrix Controller via private networks is not a fully supported scenario; please discuss this with the Aviatrix team during the planning phase before you finalize the design for the Managed CloudN deployment.

- Enter Aviatrix Controller Username/Password with an admin user credential (any users in admin RBAC Groups)

Expand Down
2 changes: 1 addition & 1 deletion HowTos/SAML_Integration_Azure_AD_IdP.rst
Original file line number Diff line number Diff line change
Expand Up @@ -125,7 +125,7 @@ Click **Single sign-on** below **Manage**
| Relay State | (leave blank) |
+----------------------------+-----------------------------------------+

|imageSAMLSettings|
The links for the SAML Identifier, Reply URL, and Sign on URL should point to the Application Gateway domain instead of the Aviatrix controller.

**User Attributes**

Expand Down
1 change: 1 addition & 0 deletions HowTos/UCC_Release_Notes.rst
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,7 @@
Release Notes
=======================================

=======
6.5.2898 (01/11/2022)
=====================

Expand Down
2 changes: 2 additions & 0 deletions HowTos/aviatrix_china_overview.rst
Original file line number Diff line number Diff line change
Expand Up @@ -46,6 +46,8 @@ What Features Are Supported in Which China Region Cloud?
+------------------------------------------------------------------------+---------------+-----------------+---------------------------+
| Firewall Network | No | No | No |
+------------------------------------------------------------------------+---------------+-----------------+---------------------------+
| Firenet | No | Yes | No |
+------------------------------------------------------------------------+---------------+-----------------+---------------------------+
| Insane Mode Encryption | No | No | No |
+------------------------------------------------------------------------+---------------+-----------------+---------------------------+
| Managed CloudN | No | No | No |
Expand Down
90 changes: 90 additions & 0 deletions HowTos/azure_saml_auth_vpn_access.rst
Original file line number Diff line number Diff line change
@@ -0,0 +1,90 @@
======================================================================
Azure Controller Security for SAML Based Authentication VPN Deployment
======================================================================

The best security practice for the Aviatrix Controller is to prevent the controller from being widely accessible from the internet. Access on TCP port 443 should be limited to:

- The range of management IPs coming from the enterprise or the datacenter.
- Ingress and egress access for basic communications and keep-alive signals from each gateway.

The exception to this best practice is when the Aviatrix Controller is used for Security Assertion Markup Language (SAML) based authentication user VPN access. In this case, the VPN user first contacts the Aviatrix Controller which then redirects user browser traffic to an Identity Provider (IdP) system, Okta for example. The initial VPN authentication traffic runs on Aviatrix Controller TCP port 443 for VPN users located off-site, so controller TCP port 443 needs to be open to all which may cause security concerns.

You must configure Aviatrix SAML authentication for your user VPN access. The SAML authentication should be configured through the Azure Application Gateway (AppGW) so the gateway access to the Aviatrix Controller is authenticated through the AppGW. The URLs generated use the AppGW domain instead of controller domain. VPN users should not access the controller directly, they should access the controller through the AppGW where access rules are enforced.

In order prevent the controller from being widely accessible and allow SAML authentication user VPN access, please follow the instructions in this section to secure your controller when Security Assertion Markup Language (SAML) based authentication is being used.

Alternative Use Cases for SAML Based User Authentication
========================================================

The Azure Application Gateway is a generic, workload agnostic reverse proxy and load balancer that includes a web application firewall (WAF).

- The service consists of Azure-managed VMs running Nginx in a VNET. Unless restricted, these VMs have access to the public internet, the VNET address space, and anything else a VM in that VNET can talk to.
- In addition to VMs, backends can be IP addresses.
- The Application Gateway is also an Ingress Controller option for the Azure Kubernetes Service.

From an Application Gateway perspective, the Aviatrix Controller is just another workload. The configurations in this section can be applied to any other HTTP or HTTPS workload. For example, you can use the Azure Application Gateway to:

- Protect an application running in an on-prem datacenter.
- Protect a hosted PaaS web application injected into the VM.
- Add HTTPS support to an older application that can only run HTTP.
- Restrict or redirect URL patterns within an application.

Prerequisites
=============

You need to understand how to configure OpenVPN SAML authentication. For more information, see `OpenVPN with SAML Authentication <https://docs.aviatrix.com/HowTos/VPN_SAML.html>`_.

Securing the Aviatrix Controller for SAML Based Authentication Behind an Azure Application Gateway
==================================================================================================

To secure your controller when Security Assertion Markup Language (SAML) based authentication is being used:

1. Create valid SSL certificates for the Aviatrix Controller and Azure Application Gateway virtual machine. Use any valid SSL certificate generation application.
2. On the Azure portal, create a subnet for the Azure Application Gateway. Create the subnet in your Aviatrix Controller’s VNET for the Azure Application Gateway. The Azure Application Gateway requires its own subnet.
3. Apply the certificates to the Controller.

- On the Aviatrix Controller, go to the Controller Settings > Security > Advanced > Controller Certificate Import Methods. The preferred method is to select “Import Certificate with Key”, you can also select “Generate CSR and Import Certificate”.
- Import the certificate files.
- After you click OK, the Aviatrix Controller browser refreshes using the new certificate. Verify the correct certificates are in use with your favorite SSL validation site.

For more information, see `Controller Certificate Management <https://docs.aviatrix.com/HowTos/import_cert_with_key.html>`_.

4. On the Aviatrix Controller, go to Settings > Controller > Access Security > Security. Enable the Controller Primary Access Account on the Controller Security Group Management card to only allow access to the Controller Public IP from Aviatrix Gateways. In the Azure Portal, the Network Security Group (NSG) assigned to the Controller is usually <controllername>-nsg.
5. On the Azure portal, create a new Azure Application Gateway:

- Specify the Basic details.
- Configure Frontends and create a Public IP.
- Create a Backend pool. Specify the NIC of the controller virtual machine as the target.
- Add a Routing Rule. Create a rule Name and enter the required values on the Listener tab.
- Enter the required values on the Backend targets tab. The Backend Target is the backend pool created earlier.
- Click Add new and configure the HTTP Settings.

A. Set the Request timeout value to 3600. Otherwise, timeouts on legitimate requests may occur.
B. Override the hostname with the FQDN chosen for the backend certificate.

6. On the Azure portal, modify the associated Azure Network Security Group to allow the Azure Application Gateway subnet.
7. On the Azure portal, enable monitoring of the Application Gateway. Add a diagnostic setting and configure the desired logging settings.
8. On the Azure portal, disable rules for the Application Gateway to prevent errors with onboarding accounts.

- Enable advanced rule configuration.
- Disable rules 200004, 931130, and 942430.

9. On the Azure portal, enable URL Rewrite to avoid Cross-Origin Resource Sharing (CORS) errors.

- Create a Rewrite set.
- Name the Rewrite set and assign it to the Aviatrix Controller routing rule.
- Rename the rule to something descriptive.
- On the Azure portal, enable URL Rewrite to avoid Cross-Origin Resource Sharing (CORS) errors.

10. On the Azure portal, put the Aviatrix Controller behind the Application which includes a web application firewall (WAF). The WAF will block requests with special entity names. Do not create entity name with special strings because the API will be blocked with a 403 error.
11. Create SAML endpoint. For more information see OpenVPN with SAML Authentication https://docs.aviatrix.com/HowTos/VPN_SAML.html.
12. Create the Azure Application Gateway.
13. onfigure the Azure Application Gateway.

.. Note:: For the HTTP Settings, when using the "Use well known CA certificate" option you may see a message about the root certificate of the server certificate used by the backend not matching the trusted root certificate added to the application gateway. To resolve this issue, use the fullchain certificate when importing the server certificate into the controller.
..

.. Note:: While authenticating the VPN user with an IdP and when sending the SAML response to the controller, you may see an error message about an invalid SAML response and the subject or username 'NoneType'. To resolve this issue, disable "override hostname" in the application gateway's controller-settings because the controller code checks the metadata and controller URL.
..


2 changes: 1 addition & 1 deletion HowTos/bgp_transitive_instructions.rst
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ Transit Network with BGP Setup Instructions

.. Important::

this document is obsolete with 3.1 release. Follow `Transit Network workflow instructions <http://docs.aviatrix.com/HowTos/transitvpc_workflow.html>`__ to setup a Transit Network.
This document is obsolete for release 3.1 and later releases. Follow `Transit Network workflow instructions <http://docs.aviatrix.com/HowTos/transitvpc_workflow.html>`__ to setup a Transit Network.

Introduction
=============
Expand Down
6 changes: 6 additions & 0 deletions HowTos/copilot_faq.rst
Original file line number Diff line number Diff line change
Expand Up @@ -105,6 +105,12 @@ Can we provide bandwidth details of links/tunnels ?
===============================================================================
If you can specify source and destination for the two endpoints of the path, i.e gateways, you will be able to obtain this information from FlowIQ by using filters.


Why do I get an error Failed to fetch Topology when I open the Topology page?
===============================================================================

If you get the error **Failed to fetch Topology data** when opening the Topology page, CoPilot was unable to access the data it needs for topology. If the issue persists, Contact Aviatrix Support.

How I can get my additional questions answered ?
===============================================================================

Expand Down
22 changes: 22 additions & 0 deletions HowTos/copilot_reference_guide.rst
Original file line number Diff line number Diff line change
Expand Up @@ -117,6 +117,9 @@ Objects on the topology maps support drag and drop. You can click, drag and drop

By default topology objects are organized using physics engines. This menu allows you to configure physical
gravity settings that manage the placement of objects. You can adjust different parameters, or turn the physics off
completely for complete control over placement of the objects.

=======
completely for complete control over placement of the objects.


Expand Down Expand Up @@ -165,6 +168,7 @@ This section describes the physics options that control how objects move in the
| | moving after having been dragged. |
+-------------------------+------------------------------------------------------------------------------------+


Performing diagnostics from Topology
-------------------------------------

Expand All @@ -176,6 +180,23 @@ To perform diagnostics from Topology (from an Aviatrix Gateway):

2. Click the DIAG button.

3. Perform any of the following diagnostic tasks for the gateway:

a. PING: Run pings directly from the gateway to outside of the Aviatrix managed network or to any resource inside the network.

b. TRACEROUTE: Run trace route.

c. Test Connectivity: Test the connectivity of the gateway to a specified host running on a specified TCP or UDP port.

d. ACTIVE SESSIONS: View sessions that are active on the selected gateway. You can filter active sessions by search criteria. For example, a search on a specific port to see if the gateway has an action session on that port.

e. INTERFACE STATS: View interface statistics about the gateway. The number of interfaces or tunnels associated with the gateway is displayed. Click on the name of an interface or tunnel to see its statistical information.
=======

1. In Topology, click on an Aviatrix Gateway in the topology map to select it.

2. Click the DIAG button.

3. Perform any of the following diagnostic tasks for the gateway:

a. PING: Run pings directly from the gateway to outside of the Aviatrix managed network or to any resource inside the network.
Expand Down Expand Up @@ -318,6 +339,7 @@ Properties of the time series panel include:
The View icon indicates a change set at that point in time. Click on a View control to load a change set; this populates the network constructs associated with the changes in the topology map and displays the details for their changes in the changes details pane. The constructs associated with the changes are circled in the map.



Working with FlowIQ
===================

Expand Down
1 change: 1 addition & 0 deletions HowTos/copilot_release_notes.rst
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,7 @@
Aviatrix CoPilot Release Notes
============================================================

=======
CoPilot Release 1.5.0 (1/12/2022)
---------------------------------

Expand Down
10 changes: 0 additions & 10 deletions HowTos/gateway.rst
Original file line number Diff line number Diff line change
Expand Up @@ -44,16 +44,6 @@ AWS Performance numbers:
+============================+=================================================+
| T2 series | Not guaranteed; it can burst up to 130Mbps |
+----------------------------+-------------------------------------------------+
| M3 series | 300 - 500Mbps |
+----------------------------+-------------------------------------------------+
| m4.xlarge, c4.xlarge | approximately 500Mbps |
+----------------------------+-------------------------------------------------+
| c3.2xlarge, m4.2xlarge | approximately 1Gbps |
+----------------------------+-------------------------------------------------+
| c3.4xlarge | approximately 1.2Gbps |
+----------------------------+-------------------------------------------------+
| c4.2xlarge | 1.2Gbps - 1.5Gbps |
+----------------------------+-------------------------------------------------+
| c5.2xlarge, c5.4xlarge | 2Gbps - 2.5Gbps |
+----------------------------+-------------------------------------------------+
| c5n.4xlarge | 25Gbps (with InsaneMode) |
Expand Down
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file added HowTos/spokegw_external_media/transitgw_bgp.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file added HowTos/spokegw_external_media/transitgw_dx.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading