Securing access to AppStream

0

Hi All,

I am currently working on an AppStream POC with the intention of streaming a web based application. I have the fleet sat in a private subnet with the intention of only allowing connections from our SIG (Zscaler). I was just looking for some advice for the best way to only allow access to the fleet from a specific IP. I have tried applying security group rules which only allow connections from the relevent IPs but I find I can still connect to the streaming instances from external networks.

Any advice / pointers would be appreciated!

preguntada hace un año678 visualizaciones
2 Respuestas
1
Respuesta aceptada

AppStream 2.0 is a managed service with managed gateways. The fleet, while sitting in a private subnet or more, are streamed through public Gateways. There is another ENI on fleet instances that are dedicated for streaming and service health, which you cannot attach Security Groups to. Now, there is the option to stream through a VPC Endpoint, forcing streaming traffic through a VPC interface - https://docs.aws.amazon.com/appstream2/latest/developerguide/creating-streaming-from-interface-vpc-endpoints.html

AWS
EXPERTO
respondido hace un año
1

This may be what you are looking for: Creating and Streaming from Interface VPC Endpoints.

profile pictureAWS
EXPERTO
kentrad
respondido hace un año

No has iniciado sesión. Iniciar sesión para publicar una respuesta.

Una buena respuesta responde claramente a la pregunta, proporciona comentarios constructivos y fomenta el crecimiento profesional en la persona que hace la pregunta.

Pautas para responder preguntas