Listing Thumbnail

    Bastion Host (Jump Box) on AWS - fail2ban & AIDE Hardened

     Info
    Sold by: Cloud SOE 
    Deployed on AWS
    AWS Free Tier
    This is a repackaged open source software product wherein additional charges apply for a pre-hardened SSH jump host with fail2ban brute-force protection, an AIDE file-integrity baseline initialised at first boot, Active Directory join tooling, Amazon CloudWatch log/metric integration, AWS Systems Manager access, and vendor support.

    Overview

    A bastion (jump) host is the single, audited entry point into a private network: administrators SSH to it and hop onward to servers that have no public exposure. This image is a minimal, pre-hardened jump host rather than a bare server image: intrusion prevention and file-integrity monitoring are installed and switched on, directory-integration tooling is present, and the host's own logs are wired into CloudWatch so its activity is visible outside the box.

    What you get out of the box

    • CIS aligned base OS hardening with an opinionated sshd configuration: key only authentication, root login disabled, modern ciphers and MACs only, strict forwarding controls
    • fail2ban tuned for SSH with sensible ban policies; UFW allowing only SSH
    • Login banners for legal notice requirements, editable for your jurisdiction
    • No listening services except SSH: no web panel, no agents, minimal attack surface by design

    Common use cases

    • Single audited door: administrators reach private EC2, RDS and container hosts through one logged channel
    • Contractor access: time boxed accounts with expiry, MFA and full session records
    • Compliance evidence: session logs and access records in your S3 bucket(optional), in formats auditors accept
    • Database tunnelling: controlled port forwarding to RDS and ElastiCache without exposing endpoints
    • MSP operations: one bastion per client VPC, deployed identically from this AMI

    Usage notes

    • To activate CloudWatch and Session Manager, attach an IAM instance role with the AWS-managed policies CloudWatchAgentServerPolicy and AmazonSSMManagedInstanceCore. No AWS credentials are stored on the image.
    • Restrict inbound TCP 22 to your administrative IP ranges in the security group, or rely on Session Manager and close port 22 entirely. Use SSH agent forwarding or ProxyJump (ssh -J) to reach internal hosts. fail2ban configuration: /etc/fail2ban/jail.local; AIDE: /etc/aide/aide.conf and /var/lib/aide/aide.db; AD join: realm join .
    • CloudWatch agent configuration: /opt/aws/amazon-cloudwatch-agent/etc/amazon-cloudwatch-agent.d/bastion-host.json.

    Sizing guidance

    Bastions are light. t3.micro suits most teams; t3.small when session recording is enabled with many concurrent users.

    Highlights

    • Purpose-built SSH jump host: fail2ban with an sshd jail (5 failures / 10 minutes / 10-minute ban) plus AIDE file-integrity monitoring whose baseline database is generated on your instance at first boot, so the integrity reference reflects your deployment, not the build.
    • Enterprise access tooling installed and ready to configure: sssd, realmd, adcli, Kerberos and Samba client libraries for joining the host to Active Directory, ntpd-rs time sync, and an SSH-hardened base (key-only authentication, root login disabled, no baked-in keys or secrets).
    • Built-in observability and access: the Amazon CloudWatch agent ships fail2ban.log, the AIDE report, syslog and auth.log (every SSH login and ban is visible in CloudWatch) and publishes host metrics under CloudSOE/bastion-host; Amazon SSM Agent enables Session Manager as a keyless alternative path; a support file identifies the exact build; vendor support from CloudSOE.

    Details

    Delivery method

    Delivery option
    64-bit (x86) Amazon Machine Image (AMI)

    Latest version

    Operating system
    Ubuntu 26.04

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Bastion Host (Jump Box) on AWS - fail2ban & AIDE Hardened

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.
    If you are an AWS Free Tier customer with a free plan, you are eligible to subscribe to this offer. You can use free credits to cover the cost of eligible AWS infrastructure. See AWS Free Tier  for more details. If you created an AWS account before July 15th, 2025, and qualify for the Legacy AWS Free Tier, Amazon EC2 charges for Micro instances are free for up to 750 hours per month. See Legacy AWS Free Tier  for more details.

    Usage costs (129)

     Info
    • ...
    Dimension
    Cost/hour
    t3.small
    Recommended
    $0.03
    t3.micro
    $0.03
    r6idn.large
    $0.03
    r5.metal
    $0.03
    r6idn.8xlarge
    $0.03
    r6i.metal
    $0.03
    r6a.16xlarge
    $0.03
    gr6.8xlarge
    $0.03
    r5a.16xlarge
    $0.03
    r6a.48xlarge
    $0.03

    AI Insights

     Info

    Dimensions summary

    You pay by the hour for the software running on your chosen Amazon EC2 instance. Every dimension here is the same Bastion Host image; they differ only by the EC2 instance type you select. Smaller burstable t3 and t3a sizes suit light SSH jump-server use. The memory-optimized r5 and r6 families, up to bare-metal and large multi-xlarge sizes, give more CPU and memory. Your hourly rate scales with the instance size you pick. You start and stop instances as needed, and charges flow through your existing AWS account on one invoice.

    Top-of-mind questions for buyers

    The hourly rate covers the Bastion Host software image running on your chosen instance. It does not include the underlying Amazon EC2 compute charge, which AWS bills separately. Both appear on your AWS invoice. Storage and data transfer are also billed by AWS on top.
    The software rate meters running hours only. A fully stopped instance accrues no hourly software charge. You still pay AWS for attached storage while the instance is stopped. Start and stop the instance as needed to control software hours.
    Every dimension is the same hardened SSH jump-server image, so choose based on CPU and memory needs. Burstable t3 and t3a sizes fit light jump-server traffic. The r5 and r6 memory-optimized families, up to bare-metal sizes, serve heavier concurrent SSH use. Your hourly rate scales with the size picked.
    cloudsoe.com+1
    Helpful?

    Vendor refund policy

    Cancel Anytime

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    64-bit (x86) Amazon Machine Image (AMI)

    Amazon Machine Image (AMI)

    An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.

    Version release notes

    Includes;

    • Latest OS patches

    Additional details

    Usage instructions

    Quick Start:

    1. SSH in as ubuntu and use this hardened host to jump to servers that are not exposed to the internet.
    2. fail2ban and AIDE intrusion detection are preconfigured.
    3. Restrict port 22 to your admin IP ranges in the security group.

    Support

    Vendor support

    Vendor support for this AMI is provided by CloudSOE. To reach the support team, email support@cloudsoe.com  with a description of your issue.

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    0 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    0%
    0%
    0%
    0%
    0 reviews
    No customer reviews yet
    Be the first to review this product . We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.