Networking & Content Delivery

Tom Adamski

Author: Tom Adamski

NetFW Proxy

Reintroducing Network Firewall Proxy for Secure Egress Connectivity

At re:Invent 2025 we launched AWS Network Firewall proxy in preview to gather feedback from customers before making it generally available. That feedback was clear and consistent: customers want the flexibility to use their Network Firewall, with all its existing capabilities, as an explicit proxy. Rather than managing a separate proxy product with its own security policy model, customers told us they would prefer […]

Securing Egress Architectures with Network Firewall Proxy

Update: We’ve updated the Network Firewall proxy preview based on customer feedback. The proxy is now a native capability of AWS Network Firewall rather than a standalone product. Note that capabilities and configuration may differ from what is described in this post. For the latest details, see Reintroducing Network Firewall Proxy for Secure Egress Connectivity. […]

Oracle Database@AWS network connectivity using Amazon VPC Lattice

As Oracle Database (ODB)@AWS becomes generally available, we’re introducing new network connectivity capabilities that streamline connectivity between Oracle Exadata infrastructure (managed by OCI) inside Amazon Web Services (AWS) data centers and users’ AWS and on-premises networks. These new features include Amazon VPC Lattice integrations for hybrid connectivity from ODB networks, and native secure access between […]

NLB TCP Idle Timeout

Introducing NLB TCP configurable idle timeout

Update: Sep 17, 2024 – Clarification added on supported listener types   This post guides you through configuring AWS Network Load Balancer (NLB) idle timeouts for Transmission Control Protocol (TCP) flows. NLB is part of the Amazon Web Services (AWS) Elastic Load Balancing family, operating at Layer 4 of the Open Systems Interconnection (OSI) model. […]

Design your firewall deployment for Internet ingress traffic flows

Introduction Exposing Internet-facing applications requires careful consideration of what security controls are needed to protect against external threats and unwanted access. These security controls can vary depending on the type of application, size of the environment, operational constraints, or required inspection depth. For some scenarios, running Network Access Control Lists (NACL) and Security Groups (SG) […]

How to automatically parse Route 53 Resolver query logs

September 8, 2021: Amazon Elasticsearch Service has been renamed to Amazon OpenSearch Service. See details. Introduction For the majority of applications, DNS resolution is an essential requirement, whether they’re running on premises or in the cloud. Inside each of your Amazon VPCs, name resolution is provided by the Route 53 Resolver service. Being the center […]

Zendesk’s Global Mesh Network: How we lowered operational overhead and cost by migrating to AWS Transit Gateway

This post is presented by our guest Vicente De Luca, Principal Engineer at Zendesk and contributor at AWS Community Builders program, focusing on architecting scalable and reliable networks for Zendesk’s global footprint, and Tom Adamski, AWS Networking Solutions Architect. Zendesk is a global CRM company, building software designed to improve customer relationships. Our customers span […]

Authenticate AWS Client VPN users with SAML

Introduction Authenticating users to applications and services on the web and at scale can be challenging. Having a separate set of credentials for each application is not an efficient approach. It is difficult to manage for IT departments and doesn’t provide a good experience for users. A common way to solve this challenge is to use […]

How to securely publish Internet applications at scale using Application Load Balancer and AWS PrivateLink

If you have applications spread across multiple Virtual Private Clouds (VPCs) and want to expose those applications to the Internet, you can choose from different approaches. One option is to give each VPC its own dedicated connectivity to the Internet through an attached Internet gateway. Another approach is to centralize access from the Internet through […]