Aller au contenu principal

Aviatrix Edge - Specifications

Aviatrix Edge

Aviatrix Edge provides an Aviatrix Cloud Connector Edge Gateway virtual device to connect your sites to cloud networks. The blueprint supports single and dual deployment modes; by default a single virtual device (one VM) is deployed. The sections below describe flavors, interfaces, software images, service-level parameters and the platform-generated provisioning outputs.

Flavors

Choose the VM flavor that matches your performance needs. The supported flavor identifiers are rendered below.

Flavors for Aviatrix Edge
StandardDPDK
Small
2 vCPU
4 GB Mem
64 GB Disk
2 vCPU
4 GB Mem
64 GB Disk
Medium
4 vCPU
8 GB Mem
64 GB Disk
4 vCPU
8 GB Mem
64 GB Disk
Large
8 vCPU
16 GB Mem
64 GB Disk
8 vCPU
16 GB Mem
64 GB Disk

In dual topology you may select a flavor for each virtual device that composes the Virtual Network Edge.

Interfaces

The diagram shows a single Aviatrix Edge VM with three customer-facing interfaces. Interfaces #1 and #3 receive platform-generated public IP addresses (shown as separate Public IP nodes). Interface #2 is the MPLS‑VPN interface and is marked optional when you do not attach any VPNs.

Common interface behaviour:

  • Public IP addresses shown for the WAN and management interfaces are platform-generated provisioning outputs, not customer-provided inputs.
  • The MPLS‑VPN interface is optional; when enabled you must provide VPN entries (see VPN list).

#1 - Internet Interface

Role: WAN / Public Internet.

  • Public IP address (WAN) — platform-assigned IPv4 address shown as a provisioning output; no customer IP value is required during standard provisioning.
  • Customer action: none required for a basic deployment; follow your cloud provider workflow if you must reserve specific public IPs prior to provisioning.

#2 - MPLS-VPN interface (optional)

Role: Connect this device to one or more MPLS‑VPN(s).

  • Activate interfaceboolean, updatable. Default: true. Set to false to leave the interface inactive for this deployment.
  • VPN listarray, updatable. Provide one or more VPN entries when attaching to MPLS‑VPNs (min 1, max 99 entries).
  • VPN Name — string, updatable. Human-friendly VPN identifier; allowed pattern: [a-zA-Z0-9-_]*.
  • VPN role — enum, updatable. One of: any-to-any, client, server.
  • BGP enable — boolean, updatable. Optional BGP configuration at the MPLS‑VPN interface level. When not enabled, no BGP-specific configuration is applied through this setting.
  • AS prepend — integer, updatable (advanced). Range: 1..6. Only relevant when BGP-related settings are used for backup VM scenarios.
  • Subnet, mask length and gateway values may be exposed as informational (non-updatable) parameters by the platform; these are reference-only in the blueprint.

Customer action: provide VPN identifiers and roles when you plan to connect to operator MPLS‑VPNs.

#3 - Internet management interface

Role: WAN / Management (Public Internet).

  • Public IP address (Management) — platform-assigned IPv4 address shown as a provisioning output; customers do not supply this value during standard provisioning.
  • Customer action: no IP input required. The management interface may be used for management and CoPilot connectivity as configured by the operator.
  • The VM-level userdata upload is allowed for management-related initial configuration (see Virtual device parameters).

Software device versions

Below are the software image versions available for Aviatrix Edge. Select the full image string when provisioning.

  • 7.0-2023-05-18
  • 7.1-2023-04-24
  • 8.0-2025-04-25
  • 8.1-2025-07-29

Routing and BGP

The BGP settings are optional and exposed on the MPLS‑VPN interface. When BGP enable is not selected, no BGP-specific configuration is applied through that setting. Advanced routing fields include VM AS number (per-VM ASN for BGP) and AS prepend (integer 1–6) when BGP is used.

Virtual device parameters

These settings apply to the Aviatrix Edge virtual device (VM):

  • VM name — hostname used as the VM identifier. Must match allowed pattern and length constraints; provide a valid hostname when creating the VM.
  • image — select the exact VM image string from the supported list displayed above.
  • flavor — choose one flavor identifier (for example: std1.c2, std1.c4, std1.c8, dpdk1.c2, dpdk1.c4, dpdk1.c8) during provisioning.
  • Userdata (cloud-init) — base64-encoded cloud-init content; upload when required by the image for initial configuration.
  • VM AS number — optional integer (1..4294967295) used for BGP when configured.

Service specific parameters

Service-specific parameters are provisioning-level inputs required by the blueprint. They are not VM-level or interface IP addresses; they are used as provisioning references.

  • Transit gateways networkslist of IPv4 CIDR values, required, not updatable. Provide one or more CIDR entries (min 1, max 9). These identify the transit gateway networks used by the service during provisioning.

    • Why the platform needs it: the blueprint requires these ranges to reference external transit networks.
    • Customer action: enter the transit gateway CIDR(s) in the service parameters when prompted. Example entries found in the deployment example: ["51.138.195.255/32", "20.19.156.87/32"].
  • Controlers networkIPv4 CIDR, required, not updatable. Network CIDR used by Aviatrix controllers as a provisioning reference.

    • Why the platform needs it: required by the blueprint to reference controller endpoints.
    • Customer action: provide the controller network CIDR (example from deployment example: 20.85.209.151/32).
  • Copilots networkIPv4 CIDR, required, not updatable. Network CIDR used by CoPilot-related provisioning references.

    • Why the platform needs it: required by the blueprint to reference CoPilot endpoints.
    • Customer action: provide the CoPilot network CIDR (example from deployment example: 172.203.138.8/32).

Provisioning outputs

The platform exposes some allocated resources as provisioning outputs. These are informational and not customer inputs:

  • Public IP address (WAN) — allocated public IPv4 address for the WAN interface; shown as a provisioning output.
  • Public IP address (Management) — allocated public IPv4 address for the management interface; shown as a provisioning output.

Licence

Only Bring Your Own Licence (BYOL) type is supported for Aviatrix Secure Edge. You need to purchase your software licence with Aviatrix sales.

Security group

For Aviatrix secure Edge, the security group are fixed for interfaces “1” and “2”. This is defined by Orange and cannot be changed :

  • Linked to interface 1 : One security group is fixed to accept only IPSEC packets allowing ingress port 500 and 4500 (Ingress UDP packets).
  • Linked to interface 3 : One security group is fixed to accept port 53 (ingress UDP packets for DNS), port 5000 and 31283 (ingress UDP packets), port 443 (ingress TCP packets for HTTPS).

To increase the security, another generic security group can be created and linked to interfaces.

Allowed Ports

Port 5000 and port 31283 needs to be allowed for Netflow communication with Aviatrix CoPilot.