Reduce Your Attack Surface with Automated Egress Filtering
The Altihex Forward Proxy Appliance is a transparent forward proxy that automatically controls outbound internet access from your EC2 instances, ECS containers, and EKS Pods. When a workload is compromised, the appliance ensures attackers cannot reach unauthorized external destinations - reducing your blast radius without manual intervention.
Pricing is usage-based and metered - see the Pricing tab for full details on dimensions and rates.
Key Benefits
Zero-touch automated configuration - Instances, containers, and pods are tagged with metadata to select host profiles. When a workload starts, a simple notification API configures the proxy automatically.
Security isolation - Proxy configuration lives in a separate security account behind a service endpoint and Gateway Load Balancer, unreachable from application accounts.
No VPC peering limits - Supports overlapping CIDR blocks across VPCs with no peering constraints.
Protocol support - Handles HTTP, HTTPS (TLS 1.2 and 1.3), multiple ports, and different transports.
Horizontal scalability - Clustered appliances gather configuration across all your accounts from a single management node, reducing AWS API requests while scaling horizontally.
How It Works
Deploy the appliance cluster in a dedicated security account behind an AWS Gateway Load Balancer and VPC service endpoint.
Define host profiles with curated domain allowlists in the security account.
Tag your workloads - Apply metadata tags to EC2 instances and ECS containers, or annotations to EKS Pods, mapping each to a host profile.
Route egress traffic - Each application account routes private outbound traffic through the service endpoint for filtering.
Automatic registration - When a new instance, container, or pod starts, the notification API registers it with the proxy cluster, enabling profile-based outbound access immediately.
Architecture Overview
The appliance sits between your application VPCs and the internet. Traffic from tagged workloads is routed through a Gateway Load Balancer endpoint to the proxy cluster in your security account. The cluster evaluates each connection against the assigned host profile's domain allowlist and permits or denies the request transparently. Configuration is centrally managed from an S3 bucket.
Example Use Case
A team running dozens of microservices across multiple AWS accounts needs to enforce outbound traffic restrictions to meet compliance requirements. Rather than maintaining per-service security group rules or NAT gateway configurations, they deploy the Altihex Forward Proxy Appliance in a central security account. Each microservice container is tagged with a host profile that permits only the specific external APIs it needs. When new services launch, they are automatically registered and filtered - no manual firewall rule changes required.
Requirements and Prerequisites
AWS Gateway Load Balancer and VPC endpoint service must be provisioned in the security account
Application accounts require route table entries directing outbound traffic to the Gateway Load Balancer endpoint
Workloads must be tagged with the appropriate host profile metadata (EC2 tags, ECS tags, or EKS annotations)
S3 bucket in the security account for centralised configuration storage
Notification API integration for automatic workload registration
Get Started
To request a guided deployment walkthrough or schedule a discovery call, contact fpa-support@altihex.com. Visit the GitHub repository for documentation and community support.
Highlights
Zero-touch egress filtering using AWS tags - EC2 instances, ECS containers, and EKS Pods are automatically configured for outbound access control by tagging workloads with host profile metadata. When a new workload starts, the notification API registers it with the proxy cluster immediately, enabling profile-based domain allowlisting without manual firewall rule changes or security group updates.
Security isolation via dedicated account architecture - The proxy configuration and appliance cluster reside in a separate security account behind an AWS Gateway Load Balancer and VPC service endpoint, completely unreachable from application accounts. This separation ensures that even if an application workload is compromised, attackers cannot tamper with egress filtering rules or bypass outbound restrictions.
Horizontal scalability with overlapping CIDR support - Clustered appliances scale horizontally from a single management node, gathering configuration across all your AWS accounts while minimising API requests. Supports overlapping CIDR blocks across VPCs without requiring VPC peering, eliminating network addressing constraints as your environment grows.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
You pay by the hour based on the EC2 instance type that runs the forward proxy appliance. All four options bill hourly and deliver the same egress filtering function. They differ only by the underlying compute. Two options run on m5-class instances, and two run on t3-class instances. Within each pair, one uses AMD-based hardware and one uses standard hardware. Pick the instance type that matches your performance and cost needs. Your total cost scales with how many instance-hours you run.
Top-of-mind questions for buyers
What does one billing hour cover for this appliance?
You are billed per hour that a proxy appliance instance runs. Each running instance of your chosen type meters one instance-hour per hour. The appliances run clustered, so charges accrue for each running node in the cluster. Stopped instances stop accruing software charges.
Am I charged when a proxy instance is stopped or the cluster scales down?
Software charges apply only while an instance runs. A stopped instance stops accruing hourly software charges. When the cluster scales down, you pay only for the nodes that keep running. Underlying AWS storage fees may still apply to stopped instances separately.
How does the hourly usage model work if I run the appliance continuously?
This is a usage-based model with no upfront commitment. Cost accrues for every hour each instance runs, so continuous operation bills 24 hours per day per node. The clustered design lets you add or remove nodes, and your bill tracks the running hours across them.
www.altihex.com
Helpful?
Vendor refund policy
At present there is no refund policy
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
For deployment assistance, troubleshooting, or questions about configuring the Forward Proxy Appliance, please open a GitHub issue with details about your environment and the problem you are experiencing. For private or security-sensitive matters, use the email channel.
To request a guided deployment walkthrough or discuss a pilot engagement, email fpa-support@altihex.com with your use case details.
Refunds
For billing questions or refund requests related to your AWS Marketplace subscription, contact fpa-support@altihex.com with your AWS account ID and subscription details.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Comprehensive application security testing using OWASP ASVS methodology to identify vulnerabilities that could lead to AWS resource abuse, data breaches, and unexpected cloud costs. Our assessment protects your AWS-hosted applications from cryptomining attacks, data exfiltration, and denial-of-wallet scenarios through systematic security testing and AWS-specific impact analysis.
A highly available, egress filtering proxy and NAT gateway. The gateway restricts HTTP and HTTPS egress traffic from VPC resources to a whitelisted set of hostnames (FQDN). This solution is effective where traditional IP-based firewalls fall short.
Deploy Squid as a caching proxy with domain-level filtering, user authentication, and ACLs to control and accelerate VPC internet access with advanced content filtering and cost optimization.
This is a repackaged open source software product wherein additional charges apply for a pre-configured, SSH-hardened Squid forward-proxy image with a tuned ready-to-use proxy configuration, Amazon CloudWatch log and metric shipping, AWS Systems Manager integration, and vendor support from Solve DevOps.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.