Frequently Asked Questions

Product Information

What is N2W and what does it offer?

N2W provides a cloud-native backup, recovery, and disaster recovery solution for Amazon Web Services (AWS) and Microsoft Azure. It offers automated backup and recovery, disaster recovery with near-instant restore, immutable backups, cost optimization features, compliance and security tools, multi-cloud management, and granular restore capabilities. N2W is used by over 1,000 organizations worldwide, including enterprises, public sector entities, and nonprofits. Note: N2W is not a replacement for AWS WAF or AWS Shield, which are focused on firewall and DDoS protection, respectively. Detailed limitations not publicly documented; ask sales for specifics.

What are AWS WAF, AWS Shield, and AWS Firewall Manager?

AWS WAF (Web Application Firewall) is a cloud firewall that uses configurable security rules to protect web applications running on AWS from attacks such as SQL injection, cross-site scripting (XSS), and brute force HTTP floods. AWS Shield is a managed Distributed Denial of Service (DDoS) protection service with two tiers: Standard (free, protects against common network and transport layer attacks) and Advanced (,000/month, adds application layer protection, real-time visibility, and DDoS Response Team access). AWS Firewall Manager provides centralized management of firewall rules and security policies across AWS accounts and integrates with both AWS WAF and AWS Shield. Note: These services are focused on network and application security, not backup or disaster recovery.

Pricing & Plans

How is AWS WAF priced?

AWS WAF charges .00 per month per Web ACL (access control list), .00 per month per rule, and .60 per 1 million web requests. Pricing is prorated hourly. Note: Additional charges may apply for resources protected by WAF. For the most current details, see the AWS WAF pricing page. N2W pricing is not covered here; see the N2W pricing page for details.

What does AWS Shield Advanced cost?

AWS Shield Advanced costs ,000 per month with a one-year subscription commitment. Additional data transfer usage fees may apply. The standard tier of AWS Shield is free for all AWS customers. Note: AWS Shield Advanced is focused on DDoS protection and does not provide backup or disaster recovery features. N2W pricing is separate and available on the N2W pricing page.

How much does AWS Firewall Manager cost?

AWS Firewall Manager costs 0.00 per policy per region. It is included at no additional charge with an AWS Shield Advanced subscription. Additional charges apply for managed resources such as firewall rules or web ACLs. Note: AWS Firewall Manager is for centralized security policy management, not backup or disaster recovery. N2W pricing is not included here; see the N2W pricing page for details.

Features & Capabilities

What security and compliance certifications does N2W have?

N2W is independently certified for ISO/IEC 27001:2022 and is SOC compliant by inheritance, leveraging AWS and Azure compliance features. N2W also supports compliance with HIPAA, GDPR, FedRAMP, ITAR, and CJIS. Customers can request a copy of the ISO certificate by contacting customer.success@n2ws.com. Note: For more details, visit the N2W Trust Center page. Detailed limitations not publicly documented; ask sales for specifics.

What integrations does N2W support?

N2W supports integrations with third-party monitoring tools such as Datadog, Splunk, and Bocada, as well as various data management and reporting tools. It offers a RESTful API and CLI access for custom automation and advanced backup management. For more details, see the N2W API documentation. Note: Some integrations may require additional configuration or licensing. Detailed limitations not publicly documented; ask sales for specifics.

Does N2W offer an API for automation?

Yes, N2W provides a RESTful API for automating tasks such as user onboarding and backup management. The API simplifies automation compared to AWS Backup, which requires Lambda scripting. Documentation and a Quick Start guide are available on the N2W website. Note: API usage may require technical expertise. Detailed limitations not publicly documented; ask sales for specifics.

Use Cases & Benefits

Who can benefit from using N2W?

N2W is designed for cloud directors, IT managers, and managed service providers (MSPs) managing AWS and Azure environments. It is suitable for enterprises with petabyte-scale data, public sector organizations needing compliance with FedRAMP, healthcare and finance industries with strict regulatory requirements, and organizations in retail, education, and nonprofit sectors seeking cost-effective backup solutions. Note: N2W is not a firewall or DDoS protection service; for those needs, consider AWS WAF or AWS Shield. Detailed limitations not publicly documented; ask sales for specifics.

What business impact can customers expect from using N2W?

Customers can achieve up to 92% savings on long-term backup costs and up to 50% on compute costs. N2W provides ransomware protection with immutable backups, near-instant recovery to minimize downtime, automated compliance reporting, and unified management across AWS and Azure. These benefits support business continuity, regulatory adherence, and operational efficiency. Note: N2W does not provide network firewall or DDoS mitigation; for those, use AWS WAF or AWS Shield. Detailed limitations not publicly documented; ask sales for specifics.

Competition & Comparison

How does N2W compare to AWS Backup?

N2W offers immutable backups, cross-cloud recovery (AWS and Azure), granular restore (file/folder-level), custom disaster recovery retention policies, intelligent storage tiering, and multi-tenancy support for MSPs. AWS Backup does not provide immutable backups, cross-cloud recovery, file/folder-level restore, or multi-tenancy. AWS Backup requires Lambda scripting for automation, while N2W provides a RESTful API. Choose N2W for advanced backup, recovery, and compliance features; choose AWS Backup for basic AWS-only backup needs. Note: AWS Backup may be preferable for organizations with simple AWS environments and no need for advanced features. Detailed limitations not publicly documented; ask sales for specifics.

Support & Implementation

How long does it take to implement N2W and how easy is it to start?

N2W implementations can be completed in as little as two weeks, supported by dedicated Customer Success Managers, onboarding calls, and detailed documentation. Customers can deploy N2W as an Amazon Machine Image (AMI) from AWS Marketplace or use CloudFormation templates. A 30-day free trial is available without a credit card. Note: Implementation time may vary based on environment complexity. Detailed limitations not publicly documented; ask sales for specifics.

Customer Proof & Case Studies

Who are some of N2W's customers?

N2W's customers include Johnson & Johnson, Dyson, HP, Western Union, Allan Gray, Skechers, Dressbarn, City of Oakland, Bahrain Ministry, St. John's University, Deutsche Bahn (DB Systel), Best Friends Animal Society, and Goodwill. For more examples and case studies, visit the N2W case studies page. Note: Customer use cases may vary; not all features are used by every customer.

Can you share specific case studies or success stories of N2W customers?

Yes. For example, Skechers standardized backup and recovery across a multi-cloud IT estate, St. John's University improved backup reliability and reduced costs, DB Systel managed petabyte-scale data with automated backup for over 1,500 volumes and 700 servers, and Gett saved 50% on cloud costs using N2W's Resource Control. For more, see the N2W case studies page. Note: Results may vary by organization and use case.

Technical Documentation & Resources

What technical documentation is available for N2W?

N2W provides user guides, release notes, RESTful API documentation, upgrade guides, and IAM permission files. These resources cover deployment, configuration, management, and compliance. Access them via the N2W documentation portal. Note: Some resources may require registration or support access. Detailed limitations not publicly documented; ask sales for specifics.

AWS WAF (Web Application Firewall) and AWS Shield: Stepping Up Your AWS Security

Share post:

Over the past couple of years, security has become a high priority for most companies. No matter what you do to keep your own infrastructure and data safe, you can still be affected by the numerous flaws in the environments your business is running on, and it’s becoming more commonplace to hear about security breaches resulting from misconfigurations.

Fortunately, there are many services available to help you improve the overall security of your AWS environment. Because most AWS services are very simple to use and don’t require management by a team of specialized employees, companies of all sizes can easily benefit from their use. This article will look at three of these services—AWS Web Application Firewall (WAF), AWS Shield, and AWS Firewall Manager—and explain why you should consider implementing them.

AWS WAF and AWS Shield

While these two services are both designed to keep your cloud environment safe, they were designed for different use cases. Let’s examine those use cases, starting with AWS WAF.

AWS Web Application Firewall

AWS Web Application Firewall (AWS WAF) is a cloud firewall that uses various security rules to protect web applications running on AWS. You can either use the security rules provided by AWS or configure your own. These rules can be implemented on a per application basis to give you flexibility.

AWS WAF was designed to be used with EC2, CloudFront, Application Load Balancer, and API Gateway. Because AWS is a fully managed service that eliminates all of your responsibilities, it is very easy to implement. There are no necessary deployments of any kind, you don’t need to install any software, and you don’t have to worry about keeping the firewall up-to-date. All you have to do is put your desired rules in place. The pricing plan for AWS WAF is also quite simple. Charges are based on the number of access control lists (Web ACLs) that you create ($5.00 per month per web ACL, prorated hourly), the number of rules you have for each web ACL ($1.00 per month per rule), and the number of web requests you receive ($0.60 per 1 million requests).

AWS WAF can be used to prevent a variety of attacks on your AWS environment. The simplest type is an attack from a known IP address, which can be stopped by configuring an IP match condition. Others are SQL injection attacks, prevented by using SQL injection match conditions, and cross-site scripting attacks (XSS attacks), prevented by cross-site scripting match conditions. AWS WAF also allows you to create a rate-based rule to stop brute force HTTP flood attacks.

AWS Shield

While AWS WAF is a firewall that can protect you from multiple types of attacks and provide various options for whitelisting, AWS Shield is a single-purpose service. AWS Shield is a managed Distributed Denial of Service (DDoS) protection tool for your AWS-based applications. DDoS attacks are malicious attacks on servers or network infrastructures that attempt to disrupt normal traffic. They’re often effective because they utilize multiple computers (usually compromised ones) as the sources of the attacks, overwhelming the target’s capacity. Since DDoS attacks are one of the most common types of attacks, having a dedicated security service for them is wise.

AWS Shield comes in two different service tiers: AWS Shield Standard and AWS Shield Advanced. The standard tier is completely free. If you’re an AWS customer, it’s already set and up and working for you. AWS Shield Standard typically protects against common network and transport layer (layers 3 and 4) DDoS attacks that target your business applications and websites. AWS Shield monitors all incoming traffic and mitigates attacks if malicious activity is detected. The service’s only downside is that, while you are protected, you can’t see an attack history, and you don’t receive any notification or report describing the attack.

AWS Shield Advanced provides much more sophisticated protection using advanced routing technology. It protects all resources running on EC2 backup, CloudFront, ELB, Route53, etc. and detects any attacks against application layers (layer 7). AWS Shield Advanced provides integration with AWS WAF and real-time visibility into attacks. This tier of service also provides 24×7 access to the AWS DDoS Response Team (DRT). If a DDoS attack does occur, and your billing increases significantly, you can be refunded for the amount you lost in the attack.

AWS Shield Advanced comes with a cost: $3,000 per month with a one-year subscription commitment. You’ll also be charged AWS Shield Advanced data transfer usage fees. For details on these, visit the AWS Shield official pricing page.

AWS Firewall Manager

AWS Firewall Manager is a service that provides a centralized place for configuring and managing firewall rules and security policies as well as for enforcing them across all applications and accounts within your AWS Organization. AWS Firewall Manager is used to simplify the use of both AWS WAF and AWS Shield.

For users running larger environments, especially those with multiple accounts, the ability to group rules and policies and apply them across an entire environment can be very helpful. AWS Firewall Manager makes it easier to bring new applications into compliance very quickly, increasing your agility. It also handles Security Groups, providing you with easy management of them through the use of a preconfigured set of rules.

AWS Firewall Manager costs $100.00 per policy per region, although it’s free with an AWS Shield Advanced subscription. Of course, you will also be charged for all the resources being managed, like firewall rules or web ACLs.

AWS WAF and AWS Shield – the optimal combination for your security

As security concerns grow, so does the need for higher-level protection of business environments running in the public cloud. Thankfully, AWS offers a whole set of managed services that greatly simplify configuration and management of these security processes. AWS WAF uses various security rules to strengthen the cloud firewall in front of your applications and ensure their uptime in the event of a malicious attack. AWS Shield provides dedicated DDoS protection meant to stop attacks on your network and servers. AWS Firewall Manager allows you to efficiently design and implement those protections across your entire cloud organization.

Whether you’re running a small startup or a large enterprise, these services can be very helpful. It’s worth your time to investigate them and make sure you properly implement them in your cloud environment.

You might also like

Achieve rapid NIS2 compliance with this checklist

Achieve rapid NIS2 compliance

Get the easy-to-follow checklist ↓