Appstream 2.0 Public IP ranges

0

Hi,

Customer who has a large Amazon Appstream 2.0 fleet wants to optimize outbound proxy/firewall configuration for access from their corporate network. Is there is please a way to identify Appstream 2.0 IP public ranges in Amazon IP ranges?

I do not see any specific service for Appstream 2.0 in Amazon Public IP ranges here.

Valid values: AMAZON | AMAZON_APPFLOW | AMAZON_CONNECT | API_GATEWAY | CHIME_MEETINGS | CHIME_VOICECONNECTOR | CLOUD9 | CLOUDFRONT | CODEBUILD | DYNAMODB | EC2 | EC2_INSTANCE_CONNECT | GLOBALACCELERATOR | KINESIS_VIDEO_STREAMS | ROUTE53 | ROUTE53_HEALTHCHECKS | S3 | WORKSPACES_GATEWAYS

Should the customer use "WORKSPACES_GATEWAYS" ? Or, how can they find the public IPs corresponding to streaming endpoints on Appstream 2.0?

Note: customer is aware they could also stream from an Interface VPC endpoint, but they also want to keep the internet access open for other use cases.

1 réponse
1
Réponse acceptée

The public IP address ranges for AppStream come out of the public address space for EC2 and CloudFront predominately.

The best bet is for the customer to allowlist the traffic to the FQDN endpoints, defined here:

https://docs.aws.amazon.com/appstream2/latest/developerguide/allowed-domains.html

Keep in mind that the traffic is web based traffic on HTTPs, so the allowlisting would likely need to occur on their web proxies.

The workspaces_gateways in the JSON file are specific to the WorkSpaces service only (and not relevant to AppStream).

Hope that helps!

AWS
EXPERT
Phil_P
répondu il y a 3 ans
profile picture
EXPERT
vérifié il y a un mois

Vous n'êtes pas connecté. Se connecter pour publier une réponse.

Une bonne réponse répond clairement à la question, contient des commentaires constructifs et encourage le développement professionnel de la personne qui pose la question.

Instructions pour répondre aux questions