Browser based remote access tool that provides easy access to hosts in all your VPCs, across accounts and regions. Windows desktops and Linux hosts are supported. No client software needed, a modern browser is all you need.
Now with AWS SSO, SAML 2.0 and Cognito integration for Single-Sign on!
Guacamole is a browser based remote access tool that provides easy access to hosts in all your VPCs, across accounts and regions. Access to Windows desktops (RDP), Linux terminals (SSH) and Kubernetes Pods is supported. No client software needed, a modern browser is all you need. This also enables administrators in corporate environments behind restrictive proxies to access remote servers on AWS.
This product ships with version 1.6.0 of the popular open-source HTML5 RDP and SSH client Apache Guacamole and GuAWS, an agent that queries your AWS environment to automatically discover running instances.
GuAWS is continuously scanning your VPC for new instances using the AWS API. It also scans across VPC, account and regional boundaries where VPC Transit Gateways or VPC Peering Connections are used. Your servers are organized by VPC and security group which makes it easy to find the right instance and manage access. Additionally, connections opened by users are logged to CloudWatch Logs.
A user management system provides fine grained access control to individual groups or instances. Single sign-on authentication can easily be added through Amazon Cognito or other OpenID compliant providers such as Auth0, Okta or Duo. Multi-Factor authentication is provided by the built-in TOTP plugin that works with Google Authenticator or similar apps. Follow the Setup Instructions link in the sidebar for additional details.
Highlights
AUTO DISCOVERY: Automatically discovers new resources in all your VPCs, cross-region, cross-account.
AUDIT LOGS: Every connection is logged to CloudWatch Logs for traceability and audit needs.
SINGLE SIGN-ON AND MFA: Enable Multi-Factor Authentication and Single Sign-On for a seamless and secure user experience.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Try this product free for 5 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time. Alternatively, you can pay upfront for a contract, which typically covers your anticipated usage for the contract duration. Any usage beyond contract will incur additional usage-based costs.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You pay by the hour based on the EC2 instance type you run. The software price is billed per hour on top of standard AWS infrastructure charges. Options span four instance families: t4g (general purpose burstable), m6g (general purpose), c6g (compute focused), and r6g (memory focused). Within each family, sizes range from medium or small up to 16xlarge. Choose a larger size to get more CPU and memory capacity. Hourly rates rise as you move to bigger instances. All options deliver the same browser-based remote access software, so pick the size that matches your workload.
Top-of-mind questions for buyers
What does one hour of billing cover for this software?
You pay the software rate for each hour the chosen EC2 instance runs. The rate is tied to the instance type you launch, such as t4g, m6g, c6g, or r6g. Software charges are added on top of the standard AWS charges for that same instance.
Am I charged the software fee when the instance is stopped?
The software fee meters running hours only. A fully stopped instance does not accrue hourly software charges. You may still see standard AWS storage fees for the attached volume while the instance is stopped, but that is separate from the software rate.
Does the instance type I pick change the features I receive?
No. Every instance type runs the same browser-based remote access software with automatic instance discovery, connection logging, and access control. The type only changes CPU and memory capacity plus the hourly rate. Pick the size that matches your expected number of concurrent connections and sessions.
docs.netcubed.io
Helpful?
Vendor refund policy
We do not currently support refunds, but you can cancel at any time.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Access the application via a browser at https://[public_dns]/. The default user is guacadmin, the default password is the instance ID. Most browsers will display a certificate warning. This warning is letting you know that the certificate was self-signed instead of signed by a trusted Certificate Authority. You can safely ignore the warning as it doesn't impact the security of the connection by clicking on "Continue to this webpage" (Internet Explorer) or "Advanced" and then "Proceed to website" (Chrome). To connect to the underlying operating system of the EC2 instance connect via SSH with the username ec2-user.
For paid support, email sales@netcubed.io for further information. Free support is provided via support@netcubed.io. For free support, we do not provide a guaranteed response time, however we do our best to respond to questions within one business day.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Supports RDP for Windows desktops, SSH for Linux terminals, and access to Kubernetes Pods through browser-based interface
Automatic Resource Discovery
Continuously scans VPCs using AWS API to automatically discover running instances across VPC, account, and regional boundaries with support for VPC Transit Gateways and VPC Peering Connections
Authentication and Authorization
Integrates with AWS SSO, SAML 2.0, Amazon Cognito, and OpenID compliant providers; includes TOTP-based multi-factor authentication compatible with Google Authenticator
Audit and Logging
Logs all user connections to CloudWatch Logs for traceability and compliance audit requirements
Fine-Grained Access Control
Provides user management system with granular access control at individual group and instance levels, with automatic organization of servers by VPC and security group
Centralized Identity and Access Visibility
Provides centralized view of identities, accounts, entitlements, and privileged access across IT estate with threat detection capabilities for compromised identities and privileged access misuse
Privileged Credential Management
Manages privileged passwords, accounts, credentials, secrets, and sessions for human and machine identities with complete control and security enforcement
Privileged Remote Access Control
Enables granular control, management, and auditing of remote privileged access for employees, vendors, developers, and cloud operations engineers with zero trust enforcement
Endpoint Privilege Management
Enforces least privilege on Windows, macOS, and Linux systems by removing local admin rights, replacing sudo with centrally managed solutions, and preventing malware and phishing attacks
Threat Detection and Analytics
Delivers advanced discovery, intelligence, and deep contextual analytics to detect threats across entire identity estate and identify hidden attack paths
Load Balancing and Traffic Management
Intelligent L4-L7 load balancing with SSL/TLS offloading and programmatic traffic manipulation capabilities
Global Server Load Balancing
Global server load balancing and high-performance DNS services for directing users to optimal app servers
DDoS and Network Security
Multi-layered DDoS protection and network security with resource and network attack mitigation
Web Application Firewall
WAF protection against application layer threats including L7 DoS, bot attacks, and OWASP top 10 attack types with regulatory compliance support for PCI-DSS, HIPAA, and FIPS 140-2
Application Access and Authentication
Application authentication supporting SAML, OAuth, and OIDC protocols with SSL VPN, Single-Sign-On, and Multi-Factor Authentication capabilities
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.