Listing Thumbnail

    Altihex Forward Proxy Appliance - AWS Egress Filtering

     Info
    Sold by: Altihex 
    Deployed on AWS
    Altihex Forward Proxy Appliance provides zero-touch egress filtering for EC2, ECS, and EKS workloads using AWS tags to reduce your attack surface.

    Overview

    Reduce Your Attack Surface with Automated Egress Filtering

    The Altihex Forward Proxy Appliance is a transparent forward proxy that automatically controls outbound internet access from your EC2 instances, ECS containers, and EKS Pods. When a workload is compromised, the appliance ensures attackers cannot reach unauthorized external destinations - reducing your blast radius without manual intervention.

    Pricing is usage-based and metered - see the Pricing tab for full details on dimensions and rates.

    Key Benefits

    • Zero-touch automated configuration - Instances, containers, and pods are tagged with metadata to select host profiles. When a workload starts, a simple notification API configures the proxy automatically.
    • Security isolation - Proxy configuration lives in a separate security account behind a service endpoint and Gateway Load Balancer, unreachable from application accounts.
    • No VPC peering limits - Supports overlapping CIDR blocks across VPCs with no peering constraints.
    • Protocol support - Handles HTTP, HTTPS (TLS 1.2 and 1.3), multiple ports, and different transports.
    • Horizontal scalability - Clustered appliances gather configuration across all your accounts from a single management node, reducing AWS API requests while scaling horizontally.

    How It Works

    1. Deploy the appliance cluster in a dedicated security account behind an AWS Gateway Load Balancer and VPC service endpoint.
    2. Define host profiles with curated domain allowlists in the security account.
    3. Tag your workloads - Apply metadata tags to EC2 instances and ECS containers, or annotations to EKS Pods, mapping each to a host profile.
    4. Route egress traffic - Each application account routes private outbound traffic through the service endpoint for filtering.
    5. Automatic registration - When a new instance, container, or pod starts, the notification API registers it with the proxy cluster, enabling profile-based outbound access immediately.

    Architecture Overview

    The appliance sits between your application VPCs and the internet. Traffic from tagged workloads is routed through a Gateway Load Balancer endpoint to the proxy cluster in your security account. The cluster evaluates each connection against the assigned host profile's domain allowlist and permits or denies the request transparently. Configuration is centrally managed from an S3 bucket.

    Example Use Case

    A team running dozens of microservices across multiple AWS accounts needs to enforce outbound traffic restrictions to meet compliance requirements. Rather than maintaining per-service security group rules or NAT gateway configurations, they deploy the Altihex Forward Proxy Appliance in a central security account. Each microservice container is tagged with a host profile that permits only the specific external APIs it needs. When new services launch, they are automatically registered and filtered - no manual firewall rule changes required.

    Requirements and Prerequisites

    • AWS Gateway Load Balancer and VPC endpoint service must be provisioned in the security account
    • Application accounts require route table entries directing outbound traffic to the Gateway Load Balancer endpoint
    • Workloads must be tagged with the appropriate host profile metadata (EC2 tags, ECS tags, or EKS annotations)
    • S3 bucket in the security account for centralised configuration storage
    • Notification API integration for automatic workload registration

    Get Started

    To request a guided deployment walkthrough or schedule a discovery call, contact fpa-support@altihex.com . Visit the GitHub repository for documentation and community support.

    Highlights

    • Zero-touch egress filtering using AWS tags - EC2 instances, ECS containers, and EKS Pods are automatically configured for outbound access control by tagging workloads with host profile metadata. When a new workload starts, the notification API registers it with the proxy cluster immediately, enabling profile-based domain allowlisting without manual firewall rule changes or security group updates.
    • Security isolation via dedicated account architecture - The proxy configuration and appliance cluster reside in a separate security account behind an AWS Gateway Load Balancer and VPC service endpoint, completely unreachable from application accounts. This separation ensures that even if an application workload is compromised, attackers cannot tamper with egress filtering rules or bypass outbound restrictions.
    • Horizontal scalability with overlapping CIDR support - Clustered appliances scale horizontally from a single management node, gathering configuration across all your AWS accounts while minimising API requests. Supports overlapping CIDR blocks across VPCs without requiring VPC peering, eliminating network addressing constraints as your environment grows.

    Details

    Sold by

    Delivery method

    Delivery option
    64-bit (x86) Amazon Machine Image (AMI)

    Latest version

    Operating system
    Ubuntu 24.04

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Altihex Forward Proxy Appliance - AWS Egress Filtering

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Usage costs (4)

     Info
    Dimension
    Cost/hour
    m5a.large
    Recommended
    $0.056
    t3a.large
    $0.056
    t3.large
    $0.056
    m5.large
    $0.056

    Vendor refund policy

    At present there is no refund policy

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    64-bit (x86) Amazon Machine Image (AMI)

    Amazon Machine Image (AMI)

    An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.

    Version release notes

    This is the initial release of the forward proxy

    Additional details

    Usage instructions

    Support

    Vendor support

    Support Channels

    GitHub Issues: Log all support issues, bug reports, and feature requests at https://github.com/Altihex/Forward-Proxy-Appliance/issues 

    Email Support: For direct support enquiries, contact fpa-support@altihex.com 

    Getting Help

    For deployment assistance, troubleshooting, or questions about configuring the Forward Proxy Appliance, please open a GitHub issue with details about your environment and the problem you are experiencing. For private or security-sensitive matters, use the email channel.

    To request a guided deployment walkthrough or discuss a pilot engagement, email fpa-support@altihex.com  with your use case details.

    Refunds

    For billing questions or refund requests related to your AWS Marketplace subscription, contact fpa-support@altihex.com  with your AWS account ID and subscription details.

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Customer reviews

    Ratings and reviews

     Info
    0 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    0%
    0%
    0%
    0%
    0 reviews
    No customer reviews yet
    Be the first to review this product . We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.