Skip to main content
Solved

Deep Dive about the Smart Group

  • July 15, 2024
  • 1 reply
  • 52 views

Zaw

Hi all: 

Currently we are creating the smart group in our environment. I would like to know about how smart group distributed to the gateway. If we create a rule with smart group with specific vpc via copilot, what will be in the gateway. will it create all gateways or only on create on specific gateway by copilot ?

Best answer by MohammedBanabila

when you create smart group will use   a tag that defined with all resources. 

for example:

  1. -can be tag a resource   with their account id of each csp
  2.  can be tag a resource to their   region of each csp

 

can be use smart group with distributed cloud firewall     when you do segmentation and enable it at transi gateway to apply all resource at spokes

note:

 

Transit Gateways are not supported as a SmartGroup resource.

Aviatrix Gateway IP addresses will not be included in any SmartGroup, even if a SmartGroup filter matches an Aviatrix Gateway IP address. If a subnet or VPC/VNet is added to an app domain, the Aviatrix Gateway IP addresses are removed from the corresponding CIDRs.

 

https://docs.aviatrix.com/documentation/latest/building-your-network/smartgroups-about.html?expand=true

link: in aviatrix cloud netorking youtube 

Distributed Cloud Firewall Demo - YouTube 

Aviatrix: Distributed Cloud Firewall (youtube.com)

 

1 reply

MohammedBanabila
Forum|alt.badge.img+5

when you create smart group will use   a tag that defined with all resources. 

for example:

  1. -can be tag a resource   with their account id of each csp
  2.  can be tag a resource to their   region of each csp

 

can be use smart group with distributed cloud firewall     when you do segmentation and enable it at transi gateway to apply all resource at spokes

note:

 

Transit Gateways are not supported as a SmartGroup resource.

Aviatrix Gateway IP addresses will not be included in any SmartGroup, even if a SmartGroup filter matches an Aviatrix Gateway IP address. If a subnet or VPC/VNet is added to an app domain, the Aviatrix Gateway IP addresses are removed from the corresponding CIDRs.

 

https://docs.aviatrix.com/documentation/latest/building-your-network/smartgroups-about.html?expand=true

link: in aviatrix cloud netorking youtube 

Distributed Cloud Firewall Demo - YouTube 

Aviatrix: Distributed Cloud Firewall (youtube.com)