Listing Thumbnail

    Squid Forward Proxy - Hardened, Tuned, CloudWatch & SSM Ready

     Info
    Sold by: Cloud SOE 
    Deployed on AWS
    AWS Free Tier
    This is a repackaged open source software product wherein additional charges apply for the pre-tuned Squid forward proxy configuration with structured access logging, Amazon CloudWatch log/metric shipping and AWS Systems Manager integration, security-hardened image preparation, and CloudSOE vendor support.

    Overview

    Open image

    Deploy a production-ready Squid proxy server on hardened AWS in minutes. Built for infrastructure and security teams who need to control, filter and log outbound web traffic from AWS workloads without spending days on installation, ACL configuration and OS hardening. Every image ships pre-patched, firewall-ready and validated.

    Why teams deploy this image

    Locked-down environments need controlled egress. Whether you are meeting compliance requirements that mandate outbound traffic inspection, reducing bandwidth costs through caching, or giving isolated subnets a single audited path to the internet, Squid remains the industry-standard forward proxy and this image removes the setup burden.

    What you get out of the box

    • Latest stable Squid release, installed and enabled on first boot
    • CIS-aligned OS hardening applied to the underlying Operating System base
    • Access logging pre-configured in a format ready for Sentinel or any SIEM ingestion
    • Support for authentication helpers (basic, LDAP, Kerberos) enable per your directory environment

    Common use cases

    • Egress control: give private subnets a single, policy-enforced internet path
    • Compliance logging: full audit trail of outbound web requests for regulated workloads
    • Bandwidth optimisation: cache repeated downloads (OS packages, container layers, updates) across a fleet
    • Web filtering: allow-list or block destinations by domain, category or time-of-day ACLs
    • Development environments: reproduce corporate proxy conditions for realistic testing

    Who this is for

    Cloud engineers, security teams, managed service providers and system administrators running AWS workloads that require governed outbound access from single VM deployments to proxy tiers behind an AWS Load Balancer.

    Usage notes

    • Attach an IAM instance role with the AWS-managed policies CloudWatchAgentServerPolicy and AmazonSSMManagedInstanceCore to activate CloudWatch and Session Manager. No AWS credentials are stored on the image.
    • Main configuration: /etc/squid/squid.conf (restrict the allowed client networks before opening the proxy port). Logs: /var/log/squid/access.log and /var/log/squid/cache.log.
    • Ports: 22/tcp (SSH), 3128/tcp (proxy).
    • CloudWatch agent config: /opt/aws/amazon-cloudwatch-agent/etc/amazon-cloudwatch-agent.d/squid.json

    Quick Start:

    • Point clients at http://:3128 (default proxy port).
    • SSH in as 'ubuntu'; configuration lives in /etc/squid/squid.conf - restrict the allowed client networks before opening the port.
    • Logs: /var/log/squid/access.log.
    • Monitoring: attach an IAM instance role with the AWS-managed policies CloudWatchAgentServerPolicy and AmazonSSMManagedInstanceCore to enable CloudWatch logs/metrics (namespace CloudSOE/squid) and Session Manager. No AWS credentials are stored on the image.

    Squid is developed by the Squid Software Foundation and community (squid-cache.org) and distributed under the GNU GPL v2. This offer packages, hardens and maintains Squid for AWS; it is not affiliated with or endorsed by the Squid project. Ubuntu is a trademark of Canonical Ltd.

    Highlights

    • Squid forward proxy pre-configured on port 3128 with a custom structured access-log format (URL, status, method, timings, source/destination IP/port, byte counts, user agent, referrer, cache action), raised file-descriptor limits (65535) and nightly log rotation.
    • In-Built integration for Active Directory and LDAP
    • Amazon CloudWatch agent pre-wired to ship Squid access/cache logs, syslog and auth.log plus host metrics (namespace CloudSOE/squid), Amazon SSM Agent for Session Manager, and vendor support from CloudSOE.

    Details

    Delivery method

    Delivery option
    64-bit (x86) Amazon Machine Image (AMI)

    Latest version

    Operating system
    Ubuntu 26.04

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Squid Forward Proxy - Hardened, Tuned, CloudWatch & SSM Ready

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.
    If you are an AWS Free Tier customer with a free plan, you are eligible to subscribe to this offer. You can use free credits to cover the cost of eligible AWS infrastructure. See AWS Free Tier  for more details. If you created an AWS account before July 15th, 2025, and qualify for the Legacy AWS Free Tier, Amazon EC2 charges for Micro instances are free for up to 750 hours per month. See Legacy AWS Free Tier  for more details.

    Usage costs (231)

     Info
    • ...
    Dimension
    Cost/hour
    t3.small
    Recommended
    $0.03
    t3.micro
    $0.03
    t2.micro
    $0.03
    i7ie.xlarge
    $0.03
    x8aedz.large
    $0.03
    m6idn.xlarge
    $0.03
    m8azn.xlarge
    $0.03
    i3.xlarge
    $0.03
    c8in.large
    $0.03
    r7a.medium
    $0.03

    Vendor refund policy

    Cancel Anytime.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    64-bit (x86) Amazon Machine Image (AMI)

    Amazon Machine Image (AMI)

    An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.

    Version release notes

    Includes the latest patches and updates for Squid and Ubuntu.

    Additional details

    Usage instructions

    Quick Start:

    1. Point clients at http://<instance-ip>:3128 (default proxy port).
    2. SSH in as 'ubuntu'; configuration lives in /etc/squid/squid.conf - restrict the allowed client networks before opening the port.
    3. Logs: /var/log/squid/access.log.

    Support

    Vendor support

    Vendor support for this AMI is provided by CloudSOE. To reach the support team, email support@cloudsoe.com  with a description of your issue.

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    0 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    0%
    0%
    0%
    0%
    0 reviews
    No customer reviews yet
    Be the first to review this product . We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.