AWS Security Blog

Category: HAQM VPC

How to add DNS filtering to your NAT instance with Squid

September 23, 2020: The squid configuration file in this blog post and associated YAML template have been updated. September 4, 2019: We’ve updated this blog post, initially published on January 26, 2016. Major changes include: support of HAQM Linux 2, no longer having to compile Squid 3.5, and a high availability version of the solution […]

How to set up an outbound VPC proxy with domain whitelisting and content filtering

November 16, 2020: We’ve updated the CloudFormation template and the launch stack URL used in this solution. July 24, 2019: We’ve added a link to a GitHub repository that contains the stack content for this solution. Controlling outbound communication from your HAQM Virtual Private Cloud (HAQM VPC) to the internet is an important part of […]

How to Connect Directly to AWS Key Management Service from HAQM VPC by Using an AWS PrivateLink Endpoint

AWS Key Management Service (AWS KMS) now supports HAQM Virtual Private Cloud (HAQM VPC) endpoints powered by AWS PrivateLink. This means you now can connect directly to AWS KMS through a private endpoint in your VPC, keeping all traffic within your VPC and the AWS network. Previously, applications running inside a VPC required internet access […]

AWS Earns Department of Defense Impact Level 5 Provisional Authorization

The Defense Information Systems Agency (DISA) has granted the AWS GovCloud (US) Region an Impact Level 5 (IL5) Department of Defense (DoD) Cloud Computing Security Requirements Guide (CC SRG) Provisional Authorization (PA) for six core services. This means that AWS’s DoD customers and partners can now deploy workloads for Controlled Unclassified Information (CUI) exceeding IL4 […]

How to Set Up DNS Resolution Between On-Premises Networks and AWS by Using Unbound

In previous AWS Security Blog posts, Drew Dennis covered two options for establishing DNS connectivity between your on-premises networks and your HAQM Virtual Private Cloud (HAQM VPC) environments. His first post explained how to use Simple AD to forward DNS requests originating from on-premises networks to an HAQM Route 53 private hosted zone. His second […]

How to Optimize and Visualize Your Security Groups

September 9, 2021: HAQM Elasticsearch Service has been renamed to HAQM OpenSearch Service. See details. May 3, 2017: We published a related blog post also written by Guy Denney, How to Visualize and Refine Your Network’s Security by Adding Security Group IDs to Your VPC Flow Logs. Many organizations start their journey with AWS by experimenting […]

How to Address the PCI DSS Requirements for Data Encryption in Transit Using HAQM VPC

The PCI requirements for encryption for data in transit are different for private networks than they are for public networks. When correctly designed, HAQM Virtual Private Cloud (HAQM VPC), a logically isolated portion of the AWS infrastructure that allows you to extend your existing data center network to the cloud, can be considered a private network, […]