This is a repackaged open source software product wherein additional charges apply for a Linux web security console. A production NGINX reverse proxy that assesses its own security, explains what it finds, and fixes what is wrong without breaking what is working. Nginx can be used for web serving, reverse proxying, caching, load balancing, media streaming, & more.
Reverse Proxy Server Solution using NGINX with Web Security Console
Nginx is an open source software solution that is highly scalable as a reverse proxy.
Nginx Reverse Proxy Features:
Reverse proxy with caching Load balancing with in-band health checks TLS/SSL with SNI and OCSP stapling support, via OpenSSL FastCGI, SCGI, uWSGI, support with caching SMTP, POP3, and IMAP proxy Keep-alive and pipelined connections support Access control based Response rate limiting WebSockets
Load balancing: A reverse proxy server sits in front of your backend servers and distributes client requests across a group of servers in a manner that maximizes speed and capacity utilization while ensuring no one server is overloaded, which can degrade performance. If a server goes down, the load balancer redirects traffic to the remaining online servers.
Web acceleration: Reverse proxies can compress inbound and outbound data, as well as cache commonly requested content, both of which speed up the flow of traffic between clients and servers. They can also perform additional tasks such as SSL encryption to take load off of your web servers, thereby boosting their performance.
Security and anonymity: By intercepting requests headed for your backend servers, a reverse proxy server protects their identities and acts as an additional defense against security attacks. It also ensures that multiple servers can be accessed from a single record locator or URL regardless of the structure of your local area network.
Includes a Security Console, by CloudInfra Appliance Manager
A production NGINX reverse proxy that assesses its own security, explains what it finds, and fixes what is wrong without breaking what is working.
Security assessment. 48 controls in 11 categories - SSH, networking, accounts and authentication, the filesystem, services, privileges, logging, updates, the firewall and NGINX itself. Every finding records what was observed and where it was read from: a file path, a kernel parameter, a systemd property, or the output of a configuration tool. A control the appliance could not evaluate is reported as an error and never counts as a pass. You get a score out of 100 with the arithmetic shown, and stored assessments so you can see what changed.
Remediation that undoes itself. Nothing is changed without being shown first, as a diff of the exact file content. Applying a fix backs up the file, validates the new configuration before it is written, applies it atomically, reloads the service, checks its health and re-runs the original control. A step that fails rolls the change back and is recorded as rolled back, not as completed with a warning. A plan that was never previewed, or previewed against a configuration that has since changed, is refused.
Configuration drift. Records the state of the files that matter, tells you when one changes, shows the diff, and restores from the backup it took at the time. Absent software is reported as not applicable, never as an error.
Firewall that will not strand you. Previews the effect of a rule before applying it, including whether it would cut your own session. Refuses outright to open the management port to 0.0.0.0/0. Arms a timer on risky changes that restores the previous firewall if you do not confirm.
Services, logs and metrics. Service state, health and control, with the units that would lock you out refused. Journal and application logs with passwords, tokens and keys removed before the text reaches your screen. CPU, memory, disk and network charted over 24 hours, plus NGINX's own figures.
Updates on your terms. Finds pending security updates and installs them only when you ask. Never automatically, never adding a package that was not already there, and never rebooting on its own.
Alerting. 12 conditions, including a stopped service, a failing control, low disk, configuration drift, firewall and SSH changes, an expiring TLS certificate and a spike in authentication failures. Delivered by email over SMTP with STARTTLS, working with Microsoft 365 and Google Workspace.
Reports and audit. Security posture, drift and audit reports, generated and downloadable. Three roles - Administrator, Operator, Viewer - enforced on every route rather than hidden in the interface, with every privileged action recorded: who, what, when, from where, and whether it worked.
Disclaimer: This product includes nginx, copyright (c) nginx, inc. and its contributors, licensed under the 2-clause bsd licence. This image is maintained by Cloud Infrastructure Services. nginx is provided "as is", without warranty of any kind, express or implied, and its authors and contributors accept no liability for any damages arising from its use.
Highlights
Reverse proxy solution that distributes client requests across a group of servers in a manner that maximizes speed and capacity utilization while ensuring no one server is overloaded, which can degrade performance. If a server goes down, the load balancer redirects traffic to the remaining online servers
Reverse proxies can compress inbound and outbound data, as well as cache commonly requested content, both of which speed up the flow of traffic between clients and servers. They can also perform additional tasks such as SSL encryption to take load off of your web servers, thereby boosting their performance.
Security & anonymity - By intercepting requests headed for your backend servers, a reverse proxy server protects their identities and acts as an additional defense against security attacks. It also ensures that multiple servers can be accessed from a single record locator or URL regardless of the structure of your local area network.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
If you are an AWS Free Tier customer with a free plan, you are eligible to subscribe to this offer. You can use free credits to cover the cost of eligible AWS infrastructure. See AWS Free Tier for more details. If you created an AWS account before July 15th, 2025, and qualify for the Legacy AWS Free Tier, Amazon EC2 charges for Micro instances are free for up to 750 hours per month. See Legacy AWS Free Tier for more details.
You pay by the hour for a preconfigured NGINX reverse proxy on Ubuntu. Billing is usage-based, so charges accrue only while the instance runs. The many dimensions map to AWS EC2 instance types, each priced per hour. Your cost depends on which instance you choose, not on a fixed plan. Smaller general-purpose types like t2 and t3 sit alongside compute-, memory-, storage-, GPU-, and bare-metal-optimized families such as c5, r5, i3, p3, and metal variants. Larger or specialized instances carry higher hourly rates. Pick the instance that matches your traffic and performance needs.
Top-of-mind questions for buyers
What does one hourly unit represent for billing on this product?
Each unit is one running EC2 instance of the type you select, billed per hour. The hourly rate covers the preconfigured NGINX software on Ubuntu for that instance. Larger or specialized instance families carry higher hourly rates. You choose one instance type and pay for the hours it runs.
Am I charged the hourly software rate when the instance is stopped?
The software rate meters running time only, so a stopped instance does not accrue software charges. Underlying AWS resources like attached storage may still incur separate AWS fees while the instance is stopped. You pay the software rate again once you restart it.
What NGINX capabilities are included regardless of which instance type I pick?
Every instance runs the same NGINX Open Source setup on Ubuntu. It supports reverse proxying, HTTP load balancing, content caching, SSL termination, and mail proxy for IMAP, POP3, and SMTP. Instance choice affects capacity and speed, not which features you get.
cloudinfrastructureservices.co.uk
Helpful?
Vendor refund policy
We do not currently support refunds, but you can cancel at any time.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Latest OS Patches installed. Simply run an update on your terminal to install the latest OS updates. "sudo apt-get update"
Additional details
Usage instructions
SSH into the EC2 instance with the following username: ubuntu
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Distributes client requests across backend servers with in-band health checks, automatically redirecting traffic to remaining online servers if a server becomes unavailable.
TLS/SSL Encryption
Supports TLS/SSL with SNI and OCSP stapling via OpenSSL for secure encrypted connections.
Caching and Compression
Implements reverse proxy caching with data compression for inbound and outbound traffic to accelerate content delivery.
Email Protocol Proxying
Functions as a proxy server for SMTP, POP3, and IMAP email protocols.
Application Server Support
Provides FastCGI, SCGI, and uWSGI support with caching capabilities for dynamic application content.
HTTPS Decryption and SSL Inspection
Deep HTTPS decryption and SSL inspection capability to filter encrypted web traffic against security policies, preventing malicious downloads, explicit content, and policy violations.
Active Directory Integration
Integration with Active Directory, LDAP, and RADIUS authentication systems to apply granular per-user and per-group filtering policies using existing directory infrastructure.
Web Filtering and Content Blocking
Web filtering proxy appliance based on Squid that blocks illegal or potentially malicious file downloads, removes advertisements, prevents access to specified website categories, and blocks resources with explicit content.
Centralized Policy Management
Centralized web-based administrative interface for defining differentiated access levels across departments, roles, and device groups without requiring additional client software.
Multi-Platform Deployment
Pre-configured deployment on AWS as an AMI running Ubuntu 26.04 and Squid 7.6, with support for Azure, VMware, and Hyper-V environments for hybrid infrastructure scenarios.
Intrusion Detection and Prevention
Intrusion Detection and Prevention System for threat identification and mitigation
VPN Connectivity
VPN connections supporting multiple Gigabit per second bandwidth for secure interconnection between VPCs, offices, and data centers
Web Proxy with Content Filtering
Web proxy with content filtering capabilities for traffic inspection and control
Quality of Service Management
Quality of Service functionality for traffic prioritization and bandwidth management
Logging and Reporting
Comprehensive logging and reporting capabilities for security monitoring and audit trails
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.