Securing access to AppStream

0

Hi All,

I am currently working on an AppStream POC with the intention of streaming a web based application. I have the fleet sat in a private subnet with the intention of only allowing connections from our SIG (Zscaler). I was just looking for some advice for the best way to only allow access to the fleet from a specific IP. I have tried applying security group rules which only allow connections from the relevent IPs but I find I can still connect to the streaming instances from external networks.

Any advice / pointers would be appreciated!

已提問 1 年前檢視次數 678 次
2 個答案
1
已接受的答案

AppStream 2.0 is a managed service with managed gateways. The fleet, while sitting in a private subnet or more, are streamed through public Gateways. There is another ENI on fleet instances that are dedicated for streaming and service health, which you cannot attach Security Groups to. Now, there is the option to stream through a VPC Endpoint, forcing streaming traffic through a VPC interface - https://docs.aws.amazon.com/appstream2/latest/developerguide/creating-streaming-from-interface-vpc-endpoints.html

AWS
專家
已回答 1 年前
1

This may be what you are looking for: Creating and Streaming from Interface VPC Endpoints.

profile pictureAWS
專家
kentrad
已回答 1 年前

您尚未登入。 登入 去張貼答案。

一個好的回答可以清楚地回答問題並提供建設性的意見回饋,同時有助於提問者的專業成長。

回答問題指南