Frequently Asked Questions

AWS Networking Services: Features & Pricing

What is AWS VPC Reachability Analyzer and how does it help with network troubleshooting?

AWS VPC Reachability Analyzer is a tool that analyzes network reachability between two endpoints within your AWS Virtual Private Cloud (VPC) or across connected VPCs. It uses automated reasoning to evaluate all resource configurations affecting connectivity, helping you identify misconfigurations or verify intended network flows without sending actual packets. This makes it valuable for troubleshooting connectivity issues and validating network changes. Note: VPC Reachability Analyzer is not free and is best used during configuration changes or when issues arise, rather than as part of continuous automation. Source: N2W blog, Feb 2021.

How much does AWS VPC Reachability Analyzer cost?

AWS VPC Reachability Analyzer is priced at .10 per analysis processed. This cost consideration means it is not intended for continuous, automated use, but rather for targeted troubleshooting and validation during network changes. Source: N2W blog, Feb 2021. Note: Pricing may change; refer to AWS documentation for the latest rates.

What is AWS Transit Gateway Connect and what are its key benefits?

AWS Transit Gateway Connect is a feature that natively integrates AWS Virtual Private Cloud (VPC) with software-defined wide area networks (SD-WANs). It simplifies the process of connecting branch offices and on-premises networks to AWS by supporting 13 vendors (including Cisco, Citrix, Sophos, Aviatrix, and Aruba) and enabling SD-WAN appliances to run on-premises or virtually in AWS. Key benefits include support for Border Gateway Protocol (BGP), Generic Routing Encapsulation (GRE), performance metrics, telemetry data, and increased bandwidth. Note: AWS Transit Gateway Connect is priced at .02 per GB of data processed. Source: N2W blog, Feb 2021.

What is AWS Network Firewall and what security features does it provide?

AWS Network Firewall is a managed, highly available (99.99% uptime) firewall service for AWS VPCs. It allows you to apply security policies and inspection points anywhere in your AWS network, supporting traffic inspection from Layer 3 to Layer 7 of the OSI model. Features include protocol and application-level inspection, pattern matching, domain name filtering, and the ability to allow or drop traffic based on IP, port, or protocol. It integrates with AWS security services and supports centralized inspection across multiple accounts via AWS Transit Gateway. Note: AWS Network Firewall is currently available in select AWS regions (US-East-1, US-West-2, EU-West-1). Source: N2W blog, Feb 2021. Limitation: Regional availability may restrict use for some organizations.

How is AWS Network Firewall priced?

AWS Network Firewall is priced at .395 per hour for each firewall running, plus .065 per GB of data processed. Traffic using NAT Gateway is not double-charged if it passes through both services. Note: Pricing and regional availability may change; always check AWS documentation for the latest details. Source: N2W blog, Feb 2021.

N2W Backup & Disaster Recovery: Features, Security, and Use Cases

What products and services does N2W offer for AWS and Azure environments?

N2W provides a cloud-native backup, recovery, and disaster recovery solution for Amazon Web Services (AWS) and Microsoft Azure. Key features include automated backup and recovery, near-instant disaster recovery, immutable backups, cost optimization (up to 92% savings on long-term backup costs), compliance and security tools, multi-cloud management, and granular restore capabilities. N2W also offers industry-specific solutions for healthcare, finance, public sector, and managed service providers (MSPs). Limitation: Detailed limitations not publicly documented; ask sales for specifics. Source: https://n2ws.com/product

What security and compliance certifications does N2W have?

N2W is independently certified for ISO/IEC 27001:2022 and is SOC compliant by inheritance, leveraging AWS and Azure compliance features. N2W also supports compliance with HIPAA, GDPR, FedRAMP, ITAR, and CJIS. Security features include immutable backups, end-to-end encryption, multi-factor authentication, and air-gapped protection. For more details, visit the N2W Trust Center. Limitation: For a copy of the ISO certificate, contact customer.success@n2ws.com. Source: https://n2ws.com/about/trust-center

What are the main pain points that N2W helps solve for cloud users?

N2W addresses high disaster recovery costs (up to 92% savings on long-term backup), downtime and data loss (near-instant recovery), ransomware threats (immutable, air-gapped backups), manual backup processes (automation), compliance challenges (automated reporting and logging), complexity in multi-cloud environments (unified console), scalability for large data volumes, and long-term backup costs (intelligent storage tiering). Limitation: Detailed limitations not publicly documented; ask sales for specifics. Source: https://n2ws.com/solutions/disaster-recovery

Who can benefit from using N2W's backup and disaster recovery solutions?

N2W is designed for cloud directors, IT managers, and managed service providers (MSPs) managing AWS and Azure environments. It is suitable for enterprises with petabyte-scale data, public sector organizations needing compliance (e.g., FedRAMP), healthcare and finance industries with strict regulatory requirements, and organizations in retail, education, and nonprofits seeking cost-effective, scalable backup. Limitation: Best fit for organizations using AWS or Azure; those on other platforms may need alternatives. Source: https://n2ws.com/product

What integrations and automation options does N2W provide?

N2W offers a RESTful API for custom integrations and automation (e.g., user onboarding, backup management), CLI access for advanced management, and integrations with third-party monitoring tools like Datadog, Splunk, and Bocada. It also supports integration with various data tools for reporting and management. API documentation is available at N2W RESTful API documentation. Limitation: Some integrations may require additional configuration or licensing. Source: https://n2ws.com/pricing

How long does it take to implement N2W, and what support is available?

N2W implementations can be completed in as little as two weeks, supported by dedicated Customer Success Managers, onboarding calls, and detailed documentation. Customers can deploy N2W as an Amazon Machine Image (AMI) from AWS Marketplace or use CloudFormation templates. Resources include video tutorials, user guides, and a knowledge base. A 30-day free trial is available without a credit card. Limitation: Implementation time may vary based on environment complexity. Source: https://n2ws.com/support

What feedback have customers given about N2W's ease of use?

Customers have praised N2W for its simplicity and user-friendly features. For example, Shane H (MSP) noted, "It's very simple to use and we are an MSP for multiple companies. Support is great and quick to respond." Julian Ware (City of Oakland) said, "You’re just clicking and going. And, to me, that’s what the modern world of backup is." These testimonials highlight ease of deployment, intuitive interface, and automation. Limitation: User experience may vary based on environment and requirements. Source: https://n2ws.com/pricing

Competition & Comparison

How does N2W compare to AWS Backup?

N2W offers several features not available in AWS Backup, including immutable backups, cross-cloud recovery (AWS and Azure), granular file/folder-level restore, custom disaster recovery retention policies, and multi-tenancy for MSPs. N2W also provides a RESTful API for automation, cost optimization (up to 92% savings), and customizable compliance reporting. AWS Backup is limited to AWS environments, lacks immutable backups and granular restore, and requires Lambda scripting for automation. Limitation: AWS Backup may be preferable for organizations seeking a basic, AWS-native backup solution without multi-cloud or advanced compliance needs. Source: https://n2ws.com/product/aws-backup

Customer Success Stories & Industries

What are some real-world examples of organizations using N2W?

Organizations such as Skechers, St. John's University, DB Systel (Deutsche Bahn), City of Oakland, Bahrain Ministry, and Gett have used N2W to achieve cost savings, improve data protection, and ensure business continuity. For example, Skechers standardized backup and recovery across a multi-cloud estate, and Gett saved 50% on cloud costs using N2W's Resource Control. For more, see N2W case studies. Limitation: Results may vary by organization and use case. Source: https://n2ws.com/solutions/case-studies

Which industries are represented in N2W's customer base?

N2W's customers span enterprises (e.g., Johnson & Johnson, Dyson, HP, Western Union), retail and e-commerce (Skechers, Dressbarn), public sector (City of Oakland, Bahrain Ministry), education (St. John's University), transportation and logistics (Deutsche Bahn), nonprofits (Best Friends Animal Society, Goodwill), healthcare and pharmaceuticals (Philips, Merck), finance and insurance, and IT/software companies. Limitation: Industry-specific features may vary; check with N2W for details. Source: https://n2ws.com/solutions/case-studies

New AWS Networking Services: VPC Reachability Analyzer & AWS Network Firewall

What is AWS Virtual Private Cloud (VPC) Reachability Analyzer? Get to know this AWS network firewall service to protect your AWS VPC.
Share post:

When people look at their cloud environment, they see their product running, whether that is a website, an application of some sort, or something else entirely. They are also aware of the infrastructure supporting that product—mostly because of the cost incurred, so the need to understand it is obvious. But there is one thing that’s often overlooked by many, particularly by those outside of the DevOps team that maintains the cloud environment: networking.

The reason for this is that networking is usually either free or one of the not-so-expensive components of the cloud, especially compared to compute instances or storage, for example. But on the AWS cloud (as well as the other major cloud providers), almost everything you do runs on the underlying networking setup, which makes networking a very crucial component in any cloud environment.

In this article, we’ll take a look at some of the recent updates introduced by AWS to its networking service, and, hopefully, you might find them useful enough to start using them yourself.

AWS Virtual Private Cloud (VPC) Reachability Analyzer

AWS Virtual Private Cloud (VPC) is a service dedicated to networking in the cloud, giving you full control of everything and anything you might need to run your cloud environment. AWS Virtual Private Cloud (PVC) covers the creation of subnets (both public and private), IP routes (along with all the firewalls used for them), NAT Gateways, VPN configurations, Elastic IP reservations, and much more. But as your business needs grow, so does the complexity of your networking in the cloud, and even the best-planned network architecture can run into issues. The problem becomes exponentially larger when you consider that you can link multiple VPCs via VPC peering or Transit Gateway, creating a massive interconnected network of resources, with multiple routes, firewall rules, etc.

A common problem, for example, is having overlapping or even conflicting configurations in place, effectively preventing your resources from communicating (and therefore even working). Another, even simpler scenario would be you placing a server in a private subnet without access to the public internet while still needing it.

AWS Backup Checklist
Fill in the gaps in your backup and DR strategy

Fortify your cloud across every critical dimension.

the disaster-proof backup & DR checklist

This is where AWS’ VPC Reachability Analyzer comes in handy, as it allows you to analyze reachability between two endpoints within your VPC (or multiple connected VPCs), and it does so without even sending packets Instead, it uses automated reasoning to look at all the resources configurations that can affect the connectivity and determines whether the network flow is possible. So, you can use it for troubleshooting network misconfigurations but also to verify your intended connectivity.

Unfortunately, VPC Reachability Analyzer isn’t free. The cost is low ($0.10 per analysis processed), but it is enough that you wouldn’t want to be running it constantly as a part of your automated processes. Instead, VPC Reachability Analyzer should only be used during networking configuration changes and to troubleshoot connectivity issues that arise.

AWS VPC and SD-WAN Native Integration Using AWS Transit Gateway Connect

Software-defined wide area networks (SD-WANs) have been used for a long time to connect branch offices to data centers and, with the introduction of cloud computing, also to extend to the cloud. This process created huge overhead—in terms of both additional setup complexity as well as maintenance needs. Up until now, to make the setup work with AWS Cloud, you had to manually provision everything, a procedure that desperately needed an upgrade.

For this reason, Amazon recently announced announced AWS Transit Gateway Connect, which is meant to natively integrate AWS Virtual Private Cloud with SD-WAN. Out of the gate, 13 vendors are already supported, including names like Cisco, Citrix, Sophos, Aviatrix, and Aruba. Plus, third-party SD-WAN appliances from these approved vendors can be physically located on-premises or run virtually on AWS Virtual Private Cloud.

This new feature supports Border Gateway Protocol (BGP), Generic Routing Encapsulation (GRE), performance metrics, telemetry data, and advanced visibility through network topology. AWS also claims that it increases total bandwidth.

AWS Transit Gateway Connect is priced at $0.02 per GB of data processed.

AWS Network Firewall

While the previous two features discussed provide some quality-of-life benefits when working with AWS, this next one is a big step in the right direction when it comes to improving security in the cloud. AWS originally only offered Security Groups (along with Network Access Control Lists) for securing your environment. Later, AWS introduced Web Application Firewall (WAF), followed by AWS Shield and AWS Firewall Manager.

AWS Network Firewall: what is it?

AWS Network Firewall is the newest addition out of AWS and quite a big one. It is a highly available (99.99%) and seamlessly scalable firewall service that is fully managed, providing you with the ability to apply blanket protections for your AWS VPC. AWS Network Firewall works with any protocol or application type, so you can inspect traffic from Layer 3 through Layer 7 (from Network to Application) of the OSI model. Traffic can be inspected whether it is leaving or entering your VPC from any direction, including inbound and outbound traffic to and from the internet, VPC-to-VPC, and VPN and AWS Direct Connect traffic. AWS Network Firewall is also integrated with the existing security services and configurations that you’re running and can coexist with them.

With AWS Network Firewall, you can simply place inspection points and security policies that you want to apply anywhere within your AWS network, without having to manage all the rules yourself. This is a huge benefit, as it removes unnecessary overhead—not only reducing the chance for a potential configuration error but also allowing you to focus your time elsewhere. So, for example, you can choose to inspect your production VPC only, or a test environment, or even an entire AWS account, if desired. AWS Network Firewall even allows you to centrally inspect multiple accounts using AWS Transit Gateway.

AWS Network Firewall additionally offers fine-grained controls, giving you the opportunity to inspect a wide range of things. To start, you can look at the IP address, port, and protocol, just like with Security Groups and Network Access Control Lists (although the ranges you can use scale much higher). General pattern matching is supported, so you can look at byte sequences within a network package. You can also inspect fully qualified domain names if needed and allow or drop traffic to certain addresses. With all of these options available, you are sure to be safe from threats like malware intrusion, protocol abuse, and many other attack attempts on your cloud environment.

AWS Network Firewall comes with an alert option as well so that you can get notifications about certain traffic, without having to interfere with it. And each drop or alert event will create a log, which can be saved in an S3 bucket or CloudWatch, or used with the Kinesis Data Firehose.

AWS Network Firewall Pricing

AWS Network Firewall does come with a price and a few considerations. For each hour of firewall running, you are going to pay $0.395. Also, each GB processed by the firewall will cost you $0.065. The upside is that for each hour and GB you’re using your AWS Network Firewall, you can use NAT Gateway free of charge—so traffic using one won’t be charged for the other.

For those of you interested in trying out AWS Network Firewall, keep in mind that this product is currently only available in US-East-1 (N. Virginia), US-West-2 (Oregon), and EU-West-1 (Dublin) AWS regions. More will be coming soon, as usual.

Summary

AWS’ three new additions to its networking ammunition are in doubt a lifesaver for troubleshooting and a step forward for automated security.

VPC Reachability Analyzer ensures that your network configurations are in order and that network reachability between important resources can be achieved. The integration between AWS VPC and SD-WAN allows for a quick and easy setup, where before it was a tedious manual task. And AWS Network Firewall steps up the security offering to a whole new level, providing numerous security features that were not available before and giving you a way to centrally manage your firewall rules for your entire networking setup in the cloud.

All of these features are fully (or at least partially) available as of now, so consider testing them out for your business needs.


You might also like