Built on the VNS3 Application Security Platform, this NATe edition provides a NAT-Gateway at a lower price with comparable performance to cloud platform NAT Gateways, while providing visibility and control for your NAT traffic needs.
Welcome to this custom, pre-configured NAT-Gateway appliance built on the Cohesive Networks VNS3 Platform that provides comparable functionality and performance but at a lower price to the cloud platform NAT Gateways.
NO DATA TAXES!
There is no additional "taxation" for your data to pass through the NATe device - except for standard cloud traffic charges.
What is included?
This device includes firewall functions allowing outbound source and port NAT-ing and can limit outbound NAT to specific ports or destination addresses. Additionally, plugins can be used to provide outbound WAF or outbound URL filtering to a small "allow list" or via connection to a URL filtering service like Webroot's BrightCloud offering.
This configuration DOES NOT include multi-cloud, site-to-site connectivity, or a number of other capabilities provided by the VNS3 Application Security Controller.
NOTE: All VNS3 controllers regardless of SKU (including this edition) can be live upgraded to provide any capabilities your cloud use-case requires.
How do I connect?
Run this instance in its own subnet with its own Route Table. In the route table for the NATe instance - set a 0.0.0.0/0 route to the VPC's Internet gateway. For other instances to use NATe as the NAT Gateway, their routing table should have a 0.0.0.0/0 route pointing to the NATe instance/network interface.
Highlights
Function as outbound NAT-Gateway using inexpensive instance types for most use-cases (No Throughput Limitation).
Firewall can be configured for secure inbound NAT using port redirection.
Allows one remote VPN user connection for secure remote admin.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
If you are an AWS Free Tier customer with a free plan, you are eligible to subscribe to this offer. You can use free credits to cover the cost of eligible AWS infrastructure. See AWS Free Tier for more details. If you created an AWS account before July 15th, 2025, and qualify for the Legacy AWS Free Tier, Amazon EC2 charges for Micro instances are free for up to 750 hours per month. See Legacy AWS Free Tier for more details.
You pay by the hour for the EC2 instance size you deploy the NATe appliance on. Each dimension maps to a specific instance type across the t2, t3, t3a, m3, m4, m5, m5a, m5ad, m5d, m5dn, m5n, and m5zn families. The instance size you pick sets your hourly software rate and the throughput available to that appliance. Smaller sizes suit lower traffic; larger sizes handle higher throughput. This software charge is separate from the AWS runtime cost for the instance, which you pay to AWS directly.
Top-of-mind questions for buyers
What does the hourly software charge cover, and what do I still pay AWS?
The hourly rate covers the NATe software license for the instance size you deploy. You pay AWS separately for the underlying EC2 instance runtime. The size you deploy sets both your software rate and your available throughput. There is no data processing fee added on top of the software charge.
Am I charged the software rate when the instance is stopped?
The software charge meters per running hour. A fully stopped instance does not accrue the hourly software rate. You may still owe AWS for attached storage while the instance is stopped. To stop all charges, terminate the instance so no runtime or storage remains.
Does deploying a larger instance size add features, or only more throughput?
Larger instance sizes give you more total throughput for the same NATe functions. The feature set stays the same across sizes, including the firewall, log access, and the plugin system for added network services. You pick a size based on expected traffic, not on which features you need.
cohesive.net+1
Helpful?
Vendor refund policy
We do not currently support refunds, but you can cancel at any time.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Version 7.1.1 is a new minor version update with Connection Advisor with AI Diagnostics (Beta), upgradable Plugins, and NIGX updates to address numerous CVEs. For more information, see the VNS3 Release Notes - https://docs.cohesive.net/docs/vns3/release-notes/.
Cohesive Networks support staff is available to help with your deployment or upgrade. Create a ticket on our support system (http://support.cohesive.net) for assistance.
Additional details
Usage instructions
Usages Instructions:
Launch the instance in its own public VPC subnet.
Create a specific Route Table associated with the VPC subnet and create a 0.0.0.0/0 destination route with the target of the VPC's Internet gateway.
Launch the VNS3 NATe Free instance in the VPC subnet created in step one using its own Security Group
Configure the VNS3 NATe security group to allow inbound traffic from any subnet address range that will be using the NATe instance as the NAT Gateway.
Disable the VNS3 NATe source/destination check.
Once the instance is running, access the UI via browser at https://<public_dns>:8000 with vnscubed as the username and the instance id as the password (See Configuration Document).
Set up other VPC subnets to use the NATe instance as the NAT Gateway by updating those associated Route Tables with 0.0.0.0/0 destination routes with a target of the NATe instance-id/network interface id.
Note: The default 0.0.0.0/0 rule enables universal initial connectivity but should be restricted to the IP(s) used for VNS3 controller management post-deployment.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Provides outbound NAT-Gateway functionality with source and port NAT-ing capabilities without throughput limitations using standard instance types.
Firewall Configuration
Includes firewall functions enabling secure inbound NAT through port redirection and outbound traffic restriction to specific ports or destination addresses.
Traffic Filtering and Control
Supports outbound WAF and URL filtering through plugins with allowlist configuration or integration with external URL filtering services.
VPN Remote Access
Enables one remote VPN user connection for secure remote administration access.
Intrusion Detection and Prevention
Intrusion detection and prevention (IPS) capabilities for threat detection and mitigation
Application Security and Visibility
Application visibility and control through AppSecure with L4-L7 security services
VPN and Secure Connectivity
IPsec and full mesh VPN termination services for secure connectivity across on-premises data centers, campuses, branches, and geographically dispersed VPCs
Cloud-Native Integration
Integration with AWS services including Elastic Load Balancer, Auto-Scaling Groups, CloudWatch, Security Hub, Key Management Service, and Gateway Load Balancer (GWLB) with L3 gateway and L4 load balancer capabilities
Advanced Routing and Network Services
Cloud-grade routing capabilities with NAT, firewall, and network address translation services
Advanced Threat Prevention Capabilities
Includes firewall, Data Loss Prevention (DLP), Intrusion Prevention System (IPS), application control, IPsec VPN, URL filtering, antivirus, and anti-bot features for multi-layered network security.
Traffic Inspection and Control
Inspects and controls encrypted data flows between on-premises networks and AWS VPCs, including North-South traffic entering and exiting private subnets and East-West traffic between VPCs.
Infrastructure-as-Code Integration
Integrates with infrastructure-as-code tools including Terraform and Ansible for policy automation, with dynamic security policy adaptation based on real-time cloud metadata.
Provides unified, centralized management through Check Point Security Management Server with consistent policy, logging, and reporting across AWS, hybrid, and on-premises environments.
Using VNS3 NATe to replace traditional NAT gateways
Reviewed on Jul 05, 2023
Review provided by G2
What do you like best about the product?
VNS3 NATe is virtual NAT gateway which is mostly used by the cloud service providers. The best part is that it provides the functionalities of the traditional NAT gateways in virtual environment and provides better security. One can use it through the AWS marketplace and can use it not just as the NAT gateway but it has firewall functionalities also. On the other hand, it is commercially also much more cheaper than the traditional NAT. The flexibility in terms of scalability is also much more better than the traditional providers.
What do you dislike about the product?
I really don't find anything big to dislike it at the first sight but there are some functional issues which sometimes irritates the administrator but I am sure these issues are manageable and won't create much dissatisfaction.
What problems is the product solving and how is that benefiting you?
VNS3 NATe built on Cohesive Networks platform is helping IT teams to build their cloud infrastructure and giving the secure environment and ability to create dockers. From my point of view, any organization which is planning to start the Cloud Journey should go with the solution as it'll not just provide NAT gateway functionality but the gateway security as well.