marketplace-ami
Boots the Enforza AWS Marketplace AMI and self-registers via the EC2 Instance Identity Document. You then claim it in the console by AWS account id plus instance id. No key to manage.
Four ready-to-deploy AWS reference architectures, from a single gateway to a GWLB fleet, each running the Enforza firewall and secure NAT as a network virtual appliance in your own account. Same egress, ingress and east-west control as the cloud-native firewall, at a flat per-firewall price with no per-GB data-processing tax.
Every pattern ships in Terraform and CloudFormation, and in two flavours that build identical networking. Only the firewall image and its bootstrap differ.
Boots the Enforza AWS Marketplace AMI and self-registers via the EC2 Instance Identity Document. You then claim it in the console by AWS account id plus instance id. No key to manage.
Boots a stock base image (Amazon Linux 2023, or Debian 12 for the GWLB pattern) and installs the engine with a one-time registration key from the console, under Onboard Firewall, Deployment Keys. No Marketplace subscription.
The firewall's network interface has its source and destination check disabled, because a forwarding appliance handles packets addressed to other hosts. Without that, the gateway would drop all transit traffic. The templates set this for you.
Grab the Terraform and CloudFormation from the public repository, or deploy from the Marketplace.
Shared private route table 0.0.0.0/0 → firewall A normally, flips to firewall B on failover
Every pattern above rides the same flat per-firewall licence. That is where the wedge comes from, and it does not move with the things the cloud-native firewalls meter.
Run Enforza on any EC2 size and the price does not change. The metered services bill by endpoint-hour, vCPU or instance size; Enforza does not.
No cap on protected IPs or network objects on the licensed plan, and no per-IP charge.
We do not licence by how many hosts you protect. Why would your firewall charge by how many things it protects?
One flat per-firewall line you can forecast, not a per-hour plus per-GB plus per-AZ plus per-add-on maze. USD $239 for 1–5 firewalls, $199 from your sixth. GBP £179 / £149.
These are deploy-ready accelerators, not just lead magnets. If you operate a fleet of firewalls for clients, a downloadable, sized, flat-priced landing zone drops the same inspected egress edge into every account you manage, at a price your clients can forecast.
The EC2 instance the appliance runs on, the internet gateway, Transit Gateway attachment and data, GWLB endpoint hours and processing, inter-AZ transfer and data-transfer-out. Enforza does not remove these; they are on your AWS bill whichever firewall you pick.
Both the cloud firewall and the Enforza EC2 can be discounted with commitments. We price on-demand US list on both sides to keep it like-for-like.
We price the AZ count each pattern actually deploys. Network Firewall adds a per-endpoint-hour fee per AZ; Enforza's resilience is your choice of how many VMs to run.
The Gateway Load Balancer's hourly and per-GB charges apply to any appliance behind it, so they are your infra cost, excluded from the appliance-licence wedge.
Match the pattern to your estate. Single gateway (S) is one VPC, secure egress for a dev or small production estate. Dual-gateway AZ failover (M) adds basic, non-production resilience to one production VPC. TGW centralised egress (L) is one inspected egress edge for a multi-VPC or multi-account estate. GWLB fleet (XL) is transparent inspection with per-AZ isolation and horizontal scale, for scale-out teams and MSP or MSSP fleets. Each is a section on this page with its own diagram, deploy notes and cost snapshot.
Both. Every pattern ships in Terraform and CloudFormation, and they build the identical topology, CIDRs and outputs, so pick whichever your team already runs. Terraform needs version 1.5 or newer; CloudFormation needs the AWS CLI.
The networking is identical, only the firewall image and its bootstrap differ. The marketplace-ami flavour boots the Enforza AWS Marketplace AMI and self-registers via the EC2 Instance Identity Document, then you claim it in the console by AWS account id plus instance id. The deployment-key flavour boots a stock base image and installs the engine with a one-time registration key from the console, so it needs no Marketplace subscription.
Up to 60–80% on the firewall and NAT metering, because Enforza is a flat per-firewall licence at $0/GB (real billable USD $239, $199 from your sixth firewall; GBP £179/£149) rather than a per-endpoint-hour, per-AZ, per-GB meter. It is a claim on the firewall and NAT charges, not on your whole AWS bill: you still pay AWS for the EC2 instance the appliance runs on, and for cloud plumbing such as the internet gateway, Transit Gateway attachment and data, GWLB endpoint hours and processing, inter-AZ transfer and data-transfer-out, which Enforza does not remove. Every figure on this page is a public US list price, dated and directional.
No, and its own README says so. It is basic, non-production resilience: failover keys off EC2 status checks (about two minutes to detect), does not sync session state (in-flight connections reset on the flip), and automatic flip-back can cause a second brief disruption. It catches a dead or hung instance, not an in-appliance degradation. For production-grade high availability, use the GWLB fleet pattern, which uses the load balancer's own health checks and horizontal scale.
Yes. The templates are validated and public, in the repository at github.com/enforza/landing-zones: each pattern in Terraform and CloudFormation, in both marketplace-ami and deployment-key flavours. Clone it, pick a pattern directory and deploy in your own account, or launch from the AWS Marketplace listing plus the console instead. Talk to us for a deploy review and we will walk you through the exact templates for your estate.
Yes, with the usual constraint: each pattern needs a region with at least two Availability Zones, and the GWLB fleet needs three (one engine and one GWLB node per AZ). The GWLB fleet's deployment-key flavour uses a Debian 12 base image, because that datapath installer needs Debian or Ubuntu rather than Amazon Linux; the marketplace-ami flavour has no such constraint.
AWS architecture icons are property of Amazon Web Services, used per their published icon terms for architecture diagrams. Enforza is an independent product and is not affiliated with, sponsored by, or endorsed by AWS.
Deploy the pattern that fits your estate, from a single gateway to a GWLB fleet, with the Enforza firewall and secure NAT in the hub. Flat per-firewall pricing, no data-processing charges. Start free, no card.