Overview
The CloudGuard Posture Management Flex for AWS offering includes:
- Protection of network entities including instances, ELBs, and RDSs at any scale
- Unlimited number of AWS accounts, VPCs and security groups
- Nano and Micro instances included at no additional cost
- One (1) year retention of audit data
- Up to ten (10) CloudGuard Posture Management Admins included at no additional cost
- SAML v2.0 SSO
- Unlimited API access
- Access to CloudGuard Posture Management mobile app
NOTES:
- Additional users above 10 cost $0.1/hour
- Usage of the Compliance Engine entails a $150 monthly surcharge (charged per CloudGuard Posture Management account, not a per host per hour)
- Compliance engine and IAM Safety are add-ons, one add-on adds 70%, and both add on adds 120% to the F1, F2, F3, F4 units reported
- Usage of the SSO entails a $400 monthly surcharge (per CloudGuard Posture Management account, not a per host per hour)
- CloudGuard Intelligence advanced data security analytics and visualization is available at additional cost
Highlights
- End-to-end security and compliance capabilities that allow you to quickly assess security posture, identify risks and gaps, fix issues, actively enforce gold standard, and prove compliance in audits
- Cloud-native, agentless protection for all AWS resources and services without the overhead of deploying and maintaining agents.
- Advanced cloud security intelligence and security analytics with CloudGuard Intelligence for faster and more efficient incident response (requires additional contract)
Details
Features and programs
Financing for AWS Marketplace purchases
Pricing
Dimension | Cost/host/hour |
---|---|
F1 tier: Small & Medium EC2 & RDS instances, Elastic Load Balancers | $0.018 |
F2 tier: Large & XLarge EC2 & RDS instances | $0.03 |
F3 tier: 2XLarge EC2 & RDS instances | $0.05 |
F4 tier: 4XL EC2 & RDS instances & above | $0.095 |
Bare Metal - all *metal* instances | $0.19 |
Additional Dome9 user above 10 | $0.10 |
Compliance Monthly Surcharge | $150.00 |
Dome9 SSO Monthly Surcharge | $400.00 |
Vendor refund policy
Service can be canceled at any time, refunds are not available
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Support
Vendor support
24x7 email support with emergency phone number. Premier support available for enterprise customers.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Similar products
Customer reviews
Convenience and Security?
Great time saver when you want and need the extra layer of security on top of cumbersome IAM policies. The ability to schedule open ports on a time expiration schedule along with restricting that access to specific external addresses and protocols fits my needs.
My last star is reserved for when they add the ability to power up and down instances on schedule.
Better overview of your security
Dome9 allows us to better visualize what are the secure parts of our network vs the ones we must monitor / enhance security on.
Some of my favorite features include:
- Dynamic Access: you can request an access by SSH or other ports for a specific duration, securing even better servers by blocking those access most of the time and validating who access the servers / when
- Clarity: gives a great overview of the network infrastructure as well as connections in / out for monitoring
- Compliance: some audits can be ran through the account to see what can be done to improve security (just wish to have some more available in the future as HIPAA / PCI are not available through marketplace for now)
- Network security: easily see what is secure and some alerts with possible remediation
- Alerts: see changes of configuration raised directly into the alerts dashboard
Some features are actually already existing within AWS, but Dome9 present them in a way that makes it much easier to manage security and bring additional tools to easily secure even better our infrastructure.
Only Authorized Users Sign In
Dome9 is a great product/service.
You can set up various security groups and integrates well with AWS. You can configure ports to be open/closed based on various options. On top of that you can set up multi-factor authentication for your Dome9 Login to help secure your account.
You can configure Dome9 to only accept SSH connections from Trusted IP's or have Time based leases. Great application and very user friendly.