The Island Network Connector virtual appliance provides zero trust network access (ZTNA) to private applications and infrastructure, replacing legacy VPNs with identity-aware, policy-driven connectivity.
Island Network OVA - Zero Trust Network Access Connector
The Island Network Connector virtual appliance provides zero trust network access (ZTNA) to private applications and infrastructure, replacing legacy VPNs with identity-aware, policy-driven connectivity. It deploys in minutes, requires no inbound firewall rules, and supports all protocols and ports.
How It Works
The connector establishes outbound-only encrypted WireGuard tunnels to Island's global network of Points of Presence (PoPs), ensuring that internal applications are never exposed to the internet. There is no need to open inbound firewall ports, set up bastion hosts, or manage complex VPN concentrators. Users access private resources based on identity and device posture - not network location.
Key capabilities include:
Outbound-only architecture - No public endpoints or inbound firewall changes required
Identity and device posture binding - Every access decision combines user identity, device health, and application context
All protocols and ports - Supports TCP, UDP, and ICMP traffic across any port
Unified policy model - The same policy engine that governs the Island Enterprise Browser extends to network access, eliminating gaps between browser and network controls
Use Case: Secure Contractor Access
Consider a scenario where external contractors need access to internal development environments or line-of-business applications. With traditional VPNs, organizations must open inbound ports, provision VPN credentials, and grant broad network access. With the Island Network OVA, contractors connect through identity-verified, policy-controlled tunnels that grant access only to specific applications - never the broader network. The contractor's device posture is continuously evaluated, and all sessions are logged in a unified audit trail alongside browser activity.
Deployment Overview
The OVA installs as a standard virtual appliance and connects outbound to Island's infrastructure. Deployment requires:
Provision the OVA in your virtualization environment or launch on Amazon EC2
Ensure outbound connectivity (UDP preferred, TCP/443 fallback) from the appliance to Island's Points of Presence.
Register the connector with your Island management console.
Define access policies binding users, device posture, and target applications.
Users connect to private resources through the Island platform.
No network rearchitecting, bastion hosts, or public-facing endpoints are needed to get started.
Getting Started
To evaluate the Island Network Connector for your environment, contact Island to schedule a guided demonstration or request a proof-of-concept deployment tailored to your infrastructure and access requirements.
Highlights
Private Application Access: The Island Network OVA connects users to internal applications without exposing those applications to the open internet. Every access decision binds identity, device posture, and application context together, so only a trusted user on a trusted device reaches a given resource, and private infrastructure stays dark to everyone else.
Unified Network Enforcement: Traffic inside your environment follows the same policy model Island applies in the browser. One set of rules governs how users reach internal apps, how data moves, and what leaves your network, which removes the gaps that appear when browser and network controls are run separately.
Deployment Without Disruption: The OVA installs as a standard virtual appliance in your virtualization platform or private cloud and connects outbound to Island in minutes. There are no inbound firewall changes, no public endpoints, and no network rearchitecting to get started.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
This connector is free software, so you pay only for the AWS compute it runs on. You choose from nine EC2 instance types, all billed hourly. The connector is a lightweight virtual machine you deploy in your private cloud or data center to enable secure remote access. Options fall into three families: t3 (t3.medium, t3.large), m5 (m5.large, m5.xlarge, m5.2xlarge), and c5 (c5.large, c5.xlarge, c5.2xlarge, c5.4xlarge). Within each family, larger sizes provide more CPU and memory. Pick the size based on your throughput needs, and deploy connectors across multiple regions if required.
Top-of-mind questions for buyers
What resources does one hourly instance charge cover, and what is the connector?
Each hourly charge covers one running EC2 instance of the size you pick. The connector is a lightweight virtual machine you deploy in your private cloud or data center. It enables secure remote access to internal applications and resources. Each instance runs independently and is billed per hour it runs.
Am I charged for a connector instance when it is stopped or powered off?
The connector software itself is free, so no software fee applies. Hourly charges reflect the underlying AWS compute time. A fully stopped instance stops accruing compute charges, though stored volumes may still incur AWS storage fees. Running instances accrue charges for each hour they are active.
How does deploying connectors across multiple regions affect what I pay?
Each connector you deploy runs as its own EC2 instance and is billed separately per hour. Running connectors in several regions multiplies the compute charges by the number of active instances. The software stays free in every region; only the AWS compute time for each running instance adds to your bill.
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Island Private Access Connector
Additional details
Usage instructions
To deploy the Island Connector, you must have an active Island tenant. If you do not have one, please contact us via our web form here: https://www.island.io/contact
Once your tenant is provisioned, access the Island Management Console at https://manage.island.io. Log in with your administrator credentials to manage your Island deployment.
For Island Connector AWS/Azure Deployment, complete the following steps:
In the Island Management Console, navigate to Network, Connectors, Add Connector to generate a registration token. Save this token for use during setup.
Launch the Island Connector image from the AWS or Azure Marketplace. Minimum instance requirements: 2 vCPUs, 4 GB RAM, 40 GB disk (e.g., AWS t3.medium or Azure Standard_D2s_v5).
Update the Security Group or Network Security Group associated with the connector instance to allow:
Inbound: TCP port 22 (SSH) from your management network for initial configuration.
Outbound: TCP port 443 (HTTPS) to Island cloud services for registration and tunnel connectivity.
SSH into the connector instance using your cloud provider key pair:
ssh -i YOUR_PRIVATE_KEY island@YOUR_CONNECTOR_PUBLIC_IP
For example: ssh -i my-key.pem island@203.0.113.25
You will be prompted to change the default password on first login.
Register the connector with your Island tenant by running:
sudo island-connector register --token YOUR_REGISTRATION_TOKEN
Once registered, the connector will appear in your Management Console under Network, Connectors. The connector will automatically update to the latest version.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Island is the developer of the Enterprise Browser - the ideal enterprise workplace, where work flows freely while remaining fundamentally secure. With the core needs of the enterprise naturally embedded in the browser itself, Island gives organizations complete control, visibility, and governance over the last mile, while delivering the same smooth Chromium-based browser experience users expect.
Island is the developer of the Enterprise Browser - the ideal enterprise workplace, where work flows freely while remaining fundamentally secure. With the core needs of the enterprise naturally embedded in the browser itself, Island gives organizations complete control, visibility, and governance over the last mile, while delivering the same smooth Chromium-based browser experience users expect.
Capgemini's Innovation Island help customers to address their needs while continuously innovating to achieve leapfrog growth in today’s market, we have designed a cloud-based platform to facilitate quick transition of products (e.g. available in marketplace) to clients' production environment.
Ferrum AI Governance Suite is the interoperable AI platform that health systems own and control. Our unified architecture breaks down data silos by connecting AI insights across service lines, enabling faster deployment, safer scaling, and measurable clinical outcomes that transform scattered tools into systematic intelligence.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.