Using Aviatrix in Public Clouds
Use Cases and Deployment Scope
Use the product to route traffic across different AWS VPC, as well as with external network outside of AWS using site to site VPN connection.
Direct east-west VPC and site to site VPN traffic to go through a 3rd party NGFW inspection.
Pros
- With a few very easy steps to establish routing between AWS VPC
- Easy procedures to establish site to site VPN connection with external parties.
- Provide network access control on routing traffic using its own build-in firewall inspection or directing traffic to 3rd party NGFW for full stack inspection.
Cons
- It lacks of ways to admin-down an established site to site VPN connections is one of the short coming.
- In network traffic inspection, it lacks options to customize the IPS function is another short coming.
- While the product allows lots of email alerting options, it lacks ways to customize the alerting email messages and ways to suppress alert flooding.
Return on Investment
- Reduce labor hours for network admin to manage public clound network routing policy.
- Build-in security features may be good enough for small/medium size companies, and thus saving money from full funciton NGFW solution.
- The Cost-IQ feature enable one to capture traffic volume of each VPC. This provides one way for the enterprise to perform cost charge back to various business funcitons at the VPC level.
Usability
Other Software Used
Cisco Firepower 4100 Series, Palo Alto Networks Next-Generation Firewalls - PA Series, SolarWinds IP Address Manager (IPAM)