Appstream 2.0 Public IP ranges

0

Hi,

Customer who has a large Amazon Appstream 2.0 fleet wants to optimize outbound proxy/firewall configuration for access from their corporate network. Is there is please a way to identify Appstream 2.0 IP public ranges in Amazon IP ranges?

I do not see any specific service for Appstream 2.0 in Amazon Public IP ranges here.

Valid values: AMAZON | AMAZON_APPFLOW | AMAZON_CONNECT | API_GATEWAY | CHIME_MEETINGS | CHIME_VOICECONNECTOR | CLOUD9 | CLOUDFRONT | CODEBUILD | DYNAMODB | EC2 | EC2_INSTANCE_CONNECT | GLOBALACCELERATOR | KINESIS_VIDEO_STREAMS | ROUTE53 | ROUTE53_HEALTHCHECKS | S3 | WORKSPACES_GATEWAYS

Should the customer use "WORKSPACES_GATEWAYS" ? Or, how can they find the public IPs corresponding to streaming endpoints on Appstream 2.0?

Note: customer is aware they could also stream from an Interface VPC endpoint, but they also want to keep the internet access open for other use cases.

1 Answer
1
Accepted Answer

The public IP address ranges for AppStream come out of the public address space for EC2 and CloudFront predominately.

The best bet is for the customer to allowlist the traffic to the FQDN endpoints, defined here:

https://docs.aws.amazon.com/appstream2/latest/developerguide/allowed-domains.html

Keep in mind that the traffic is web based traffic on HTTPs, so the allowlisting would likely need to occur on their web proxies.

The workspaces_gateways in the JSON file are specific to the WorkSpaces service only (and not relevant to AppStream).

Hope that helps!

AWS
EXPERT
Phil_P
answered 3 years ago
profile picture
EXPERT
reviewed 21 days ago

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.

Guidelines for Answering Questions