AWS securing outbound communication in private subnet

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

AWS securing outbound communication in private subnet

L1 Bithead

I've a private subnet in AWS that needs to be locked out from Internet access. But the instances in this private subnet need to access specific set of hosts (say update.java.com, update.ubuntu.com etc). Obviously the IP address associated with these hosts are dynamic. Does Palo Alto Networks Firewall (or any other solution) solve this scenario? If so, please provide pointers. 

 

5 REPLIES 5

L6 Presenter

Hi Foobar,

 

You can create custom URL and allow internet traffic for those URL for a specific subnet.

 

Please refer the following doc.

https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Create-Custom-URL-Categories/ta-p...

 

-- Hardik Shah

 

 

Thanks Hardik.

 

I'm assuming this solution is available in Palo Alto Networks VM-series Next-Gen Firewall Bundle 1/2 in AWS Marketplace. Please confirm.

PAYG2 will have support for URL Filtering

https://live.paloaltonetworks.com/t5/AWS-Azure-Articles/VM-Series-for-AWS-and-Azure-Licensing-Consid...

 

If all you need to do is create a customer URL category and define the URLs then you shouldn't need a URL filtering license for that. But if you want URL filtering then PAYG2 is the way to go there. 

I Agree ...

Thanks.

 

Is there a template readily available to deploy a simple solution for this usecase in AWS?

From link, I guess I'm trying to implement "Use Case: Secure the EC2 Instances in the AWS Cloud" section. Looking for a template that I leverage.

 

Thanks.

  • 4825 Views
  • 5 replies
  • 1 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!