Landing zones

Pre-built cloud landing zones with a flat-priced firewall in the hub.

Ready-to-deploy AWS and Azure reference architectures that drop the Enforza firewall and secure NAT into the hub of your network. Same egress, ingress and east-west control as the cloud-native firewall, at a flat per-firewall price with no per-GB data-processing tax. Deployed your team's way, in your own account.

Which one are you

Find the pattern that fits your estate

Pick your cloud, then your size. Each tile jumps to its section, or deploys straight from here.

AWS landing zones

Four patterns, in Terraform and CloudFormation.

Azure landing zones

Three from-scratch Terraform patterns.

Pick your cloud

AWS and Azure, ready to deploy

AWS landing zones

Four real, validated patterns, in Terraform and CloudFormation and in two deploy flavours: single gateway, dual-AZ failover, TGW centralised egress, and a GWLB fleet. Each with its own diagram, deploy notes and a dated cost snapshot.

Explore AWS patterns

Azure landing zones

Three from-scratch Terraform patterns that build the whole network: simple single-AZ, HA multi-AZ across availability zones behind an internal load balancer, and HA multi-AZ with DNAT for published services. Plus the drop-in Marketplace or ARM appliance for a hub you already run.

Explore Azure patterns

All the Terraform and CloudFormation lives in one public repository, AWS and Azure alongside each other. Clone it, pick a pattern directory and deploy in your own account.

Why put it in the hub

One inspected egress edge, at a price you can forecast

Same control, flat pricing

Egress, ingress and east-west control with FQDN and SNI-based Layer 7 filtering, at a flat per-firewall licence with no per-GB data-processing tax. See pricing and the feature list.

Secure NAT included

The appliance source-NATs outbound, so it replaces the NAT gateway and filters egress in one hop. More on the secure NAT gateway.

Your network, your data

It runs on a VM in your own account and streams logs to your own SIEM, never via Enforza's cloud. See how it works.

Drop the per-GB tax

Priced against the cloud-native firewalls, the wedge is up to 60–80% on the firewall and NAT metering. Compare vs AWS Network Firewall and vs Azure Firewall.

For MSPs and CSPs

Put a flat-priced firewall in every hub you build

If you operate a fleet of firewalls for clients, a sized, flat-priced landing zone is a partner-usable accelerator: the same inspected egress edge in every account you manage, at a price your clients can forecast.

FAQ

Landing zones, common questions

What is a landing zone, and why put the firewall in the hub?

A landing zone is the baseline network and account structure you deploy workloads into. Centralising egress through a firewall in the hub means one inspected, policy-controlled path to the internet for every workload, instead of a NAT gateway or firewall per VPC. Enforza sits in that hub slot as a network virtual appliance, doing secure NAT and Layer 7 egress filtering at a flat per-firewall price.

Which clouds are covered today?

Both are ready to deploy. AWS has four validated patterns, from a single gateway to a GWLB fleet, in Terraform and CloudFormation. Azure has three from-scratch Terraform patterns (simple single-AZ, HA multi-AZ, and HA multi-AZ with DNAT) plus the drop-in single-appliance deploy into a hub you already run, one-click from the Azure Marketplace or via the ARM template. All the templates are in the public repository. Pick your cloud from the two cards above.

How much can a flat-priced firewall in the hub save?

Up to 60–80% on the firewall and NAT metering versus the cloud-native services, because Enforza is a flat per-firewall licence at $0/GB rather than a per-endpoint-hour, per-AZ, per-GB meter. It is a claim on the firewall and NAT charges, not your whole cloud bill: you still pay your cloud provider for the VM the appliance runs on and for cloud plumbing, which Enforza does not remove. Run your own numbers in the savings calculator.

Same control, flat pricing, your team's way.

Put a flat-priced firewall in your hub.

Deploy the pattern that fits your estate on AWS or Azure, with the Enforza firewall and secure NAT in the hub. Flat per-firewall pricing, no per-GB tax. Start free, no card.