
Overview
The Hillstone CloudEdge Virtual-Firewall (BYOL) version can switch among VM01/02/04/08 based on licenses. It supports 2-4-core EC2 instance providing high performance. The Hillstone Virtual Firewall allows you to provision firewall security whenever and wherever it is needed. It features most of the networking services common to Hillstone's hardware based appliances and is an ideal solution for protecting network resources within AWS. It offers enhanced access control, Virtual Private Network (VPN), L2-L7 attack protection, and server load balancing for AWS users. With the addition of the virtual firewall, Hillstone offers greater choice and exibility by providing the ability to deploy a mix of hardware and virtual appliances operating together. In 5.5R6, VM01 supports up to 100k concurrent sessions, max 100 IPSec VPN tunnels and max 100 SSL VPN users; VM02 supports up to 500k concurrent sessions, max 500 IPSec VPN tunnels and max 500 SSL VPN users; VM04 supports up to 5M concurrent sessions, max 10000 IPSec VPN tunnels and max 2000 SSL VPN users. For detail, please refer the datasheet in Additional Resources.
Highlights
- The CloudEdge enables north-south traffic inspection to provide the VPC network with dedicated security isolation via policy control, as well as granular access control, QoS, VPN,IPS and server load balancing to guarantee business continuity
- The CloudEdge offers IPSec VPN and SCVPN for endpoint and hybrid-cloud, standards-based site-to-site VPN connections are established between the corporate local network, branches and your AWS virtual service
- The CloudEdge provides server load balancing, helping enterprises establish an EC2 cluster on AWS traffic can be assigned equally to different EC2 instances, all providing the same service.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Vendor refund policy
We do not currently support refunds, but you can cancel at any time.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
First Release
Additional details
Usage instructions
How to deploy Virtual Firewall on AWS: https://www.hillstonenet.com/wp-content/uploads/CloudEdge-Deployment-Guide-6.pdf
Resources
Support
Vendor support
Please allow 24 hours You can depend on Hillstone Networks remote support services for expert, timely technical resources to help you maintain network security and protect your business 24x7. In addition to real-time online support, you may access our experienced, certified engineers through toll-free hotlines.For details, please contact Hillstone at 1-800-889-9860.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Similar products
Customer reviews
Cloud security has improved and supports compliant operations across development and production
What is our primary use case?
We have utilized Hillstone virtual firewalls to secure cloud-hosted solutions, including recharge service platforms and applications operating across development and production environments.
How has it helped my organization?
We have enhanced the security of cloud-hosted solutions and ensured they are deployed and operated within a secure, reliable, and compliant environment.
What is most valuable?
Hillstone CloudEdge Virtual Firewall provides advanced security for cloud and virtualized environments through next-generation firewall (NGFW) capabilities, including application visibility and control, intrusion prevention (IPS), antivirus protection, VPN services, threat intelligence, and advanced attack defense mechanisms. It supports deployment across major public and private cloud platforms such as Microsoft Azure, AWS, VMware, and OpenStack, enabling consistent security policies in hybrid and multi-cloud architectures.
What needs improvement?
There is room for improvement in Value-Added Services and Information Technology departments.
For how long have I used the solution?
I have used Hillstone CloudEdge for approximately two years.
Which solution did I use previously and why did I switch?
I used Huawei, but it was due for End Of Support Life.
What's my experience with pricing, setup cost, and licensing?
The setup cost is more expensive with similar features.
Centralized security has protected hybrid workloads and provides deep visibility into cloud traffic
What is our primary use case?
My primary use case is twofold: as a centralized VPN concentrator —terminating site-to-site IPsec tunnels to remote offices and providing secure remote access via SSL VPN— and as a perimeter firewall for the edge of my virtualized workloads.
CloudEdge inspects north-south traffic toward my virtual instances by applying intrusion prevention (IPS) and inline antivirus, complemented by application identification and policy-based control.
With this, I protect the data of my main systems against intrusions, malware, and malicious traffic, while maintaining visibility and granular control over inbound and outbound connections.
How has it helped my organization?
CloudEdge consolidated VPN, IPS, and antivirus into a single virtual appliance, reducing operational complexity and cost compared to tier-one solutions.
We gained full visibility into north-south traffic toward our virtual instances and granular policy-based control, which strengthened our perimeter security posture.
Inline inspection reduced the exposure surface of our critical systems against intrusions and malware, while the centralized termination of IPsec and SSL VPN tunnels simplified secure connectivity with remote offices and remote-access users.
In addition, CloudEdge has helped us apply consistent security controls across both our AWS workloads and our on-premises workloads.
It provides an additional security layer beyond basic security groups and network ACLs, allowing us to inspect traffic more closely and enforce more detailed and specific policies.
What is most valuable?
The most valuable features for us have been:
Intrusion prevention (IPS) and inline antivirus: real-time threat inspection on north-south traffic allows us to block intrusions and malware before they reach our critical systems, without relying on external controls or a second inspection layer.
VPN termination (IPsec and SSL): consolidating site-to-site tunnels to remote offices and secure remote access on the same appliance simplified our connectivity architecture and reduced administration points.
Behavioral analysis and anomaly detection: this is one of Hillstone's key differentiators; anomalous-traffic detection gives us visibility depth beyond traditional signatures, helping us identify suspicious patterns that a conventional firewall would miss.
Traffic visibility and logging: granular logs and full connection visibility let us audit, correlate events, and tune policies based on concrete data, which is essential for daily operations and compliance.
Deployment flexibility: being able to deploy the same virtual appliance both in public cloud and on our own hypervisor lets us apply consistent security controls across hybrid environments, without fragmenting our security policy between platforms.
What needs improvement?
Cloud-native automation and IaC: Terraform support, auto-scaling templates, and API maturity lag behind Palo Alto VM-Series and FortiGate-VM.
Dynamically scaling in public cloud requires more manual effort.
Third-party integrations and ecosystem: fewer native connectors with SIEM/SOAR platforms, CSPM, and third-party tools compared to market leaders.
Documentation and training material: technical documentation and community resources (forums, tutorials, KB) are more limited, which lengthens the learning curve for new teams.
SASE/SSE capabilities: the integrated SASE/ZTNA offering is less mature compared to the convergence already provided by Fortinet or Palo Alto.
Centralized multi-instance management: managing large fleets of virtual appliances could be smoother; centralized management (HSM) works, but some users would like more granularity and automation.
For how long have I used the solution?
I have used it for 5 years.
Which solution did I use previously and why did I switch?
We previously used Fortinet (FortiGate) and migrated to Hillstone CloudEdge.
The decision was primarily driven by the cost/performance ratio: Hillstone offered us a comparable feature set —NGFW firewall, IPS, antivirus, and VPN termination— at a lower total cost of ownership, with a more flexible licensing model for virtualized and cloud environments.
Additionally, we valued the depth of Hillstone's behavioral analysis and anomaly detection capabilities, which aligned well with our visibility requirements.
The migration allowed us to maintain our existing security posture while optimizing the investment, without sacrificing inspection or secure-connectivity capabilities.
What's my experience with pricing, setup cost, and licensing?
My main recommendation is to evaluate the total cost of ownership (TCO) over a three-year horizon, not just the initial acquisition or licensing price.
That is where Hillstone CloudEdge shows its greatest advantage: when comparing the accumulated cost of licenses, security subscriptions, support, and renewals against alternatives like Palo Alto or Check Point, the differential is usually significant in Hillstone's favor, while maintaining a comparable feature set.
I advise building the analysis around the full lifecycle including subscription renewals and projected instance growth to properly size the real savings.
When evaluated from that perspective, the cost/performance ratio becomes a compelling argument.
Which other solutions did I evaluate?
Before making our decision, we evaluated other NGFW alternatives, primarily Palo Alto Networks (VM-Series) and Check Point (CloudGuard).
Both are strong, well-recognized solutions in the market, but in our cost-benefit analysis Hillstone CloudEdge offered the best balance: a comparable feature set NGFW, IPS, antivirus, VPN, and behavioral analysis at a significantly lower total cost of ownership, with a more flexible licensing model for virtualized and cloud environments.
Palo Alto and Check Point stand out in ecosystem maturity and integrations, but for our operational requirements, the price differential did not justify the additional investment, especially given our in-house expertise with the Hillstone platform.
That combination of capabilities, flexibility, and cost was what tipped the decision.
What other advice do I have?
On balance, Hillstone CloudEdge is a solid and highly competitive solution within the virtual NGFW firewall segment.
Its greatest strength is the cost/performance ratio: it delivers a feature set comparable to that of the market leaders NGFW, IPS, antivirus, VPN, and behavioral analysis at a considerably lower total cost of ownership, which makes it an especially attractive option for hybrid environments and organizations looking to optimize their security investment without sacrificing inspection capabilities.
Consistent cloud and on-prem security has protected workloads and provides granular traffic control
What is our primary use case?
We deploy Hillstone CloudEdge Virtual-Firewall in AWS to protect workloads hosted inside our VPC. We use it to inspect north-south traffic, enforce access-control policies, secure communication between environments, and protect internet-facing applications and servers. Our main requirements include firewall policy enforcement, VPN connectivity, intrusion prevention, application control, and improved visibility into network traffic. The Hillstone model is suitable for our cloud environment because it gives us flexibility.
How has it helped my organization?
CloudEdge has helped us apply consistent security controls to our AWS workloads with our on-premises workloads. It provides an additional security layer beyond basic security groups and network ACLs. This allows us to inspect traffic more closely and enforce more detailed policies.
What is most valuable?
The most valuable aspect is the combination of traditional firewall functionality with cloud deployment flexibility. Important features include granular access control, IPsec and SSL VPN, intrusion prevention, antivirus, application control, traffic monitoring, and attack protection. The interface is relatively straightforward for administrators who already have firewall experience. The firewall integrates well into an AWS VPC architecture and provides useful control over traffic entering and leaving protected networks. The CloudEdge uses the same StoneOS platform as Hillstone's physical security appliances. This helps maintain a consistent configuration and management experience across physical and virtual environments.
What needs improvement?
Additional automation resources for AWS would also be helpful. More comprehensive CloudFormation or Terraform examples, deployment templates, and guidance for high-availability architectures could make larger implementations easier.
For how long have I used the solution?
I have used the solution for three years.