This is a repackaged open-source software product, with additional charges for a pre-hardened SSH jump host with fail2ban intrusion blocking, AIDE integrity checking, Active Directory/SSSD join tooling, Amazon CloudWatch log and metric shipping, the AWS Systems Manager agent, and vendor support.
Managing Linux and Windows servers in private subnets requires a secure, reliable gateway that keeps bad actors out while letting authorized administrators in. The Bastion Host gives you that gateway: a hardened, purpose-built entry point to your cloud infrastructure that eliminates the complexity of VPNs.
Why You Need a Bastion Host
Your servers sit behind firewalls and security groups for good reason. But when you need to manage those systems, you need a secure path in. A bastion host acts as a single, fortified access point between the public internet and your private network. All administrative SSH and RDP sessions route through this controlled entry point, giving you centralized access management and audit visibility.
With built-in intrusion protection, multi-factor authentication, and key-based authentication, the Bastion Host on AWS ensures that only authorized personnel reach your private servers -- whether they run Linux, Windows, or macOS.
Key Features and Security Capabilities
Multi-Factor Authentication (MFA) Support - Add a second layer of verification beyond passwords and keys to prevent unauthorized access
Multi-Operating System Support - Connect to and manage Linux, Windows, and macOS systems from a single bastion host
Intrusion Detection and Protection - Automatically blocks any IP address that repeatedly fails SSH authentication for 10 minutes, stopping brute-force attacks in real time
Firewall Protection - Built-in firewall rules restrict traffic to only what is necessary for secure administration
Key-Based Authentication - Supports SSH public key authentication for secure, passwordless connections to your bastion host
Lean Deployment - Minimal footprint with only the packages needed for secure access, reducing your attack surface
Built on Ubuntu 20.04 - Based on a stable, well-supported Ubuntu LTS release
How It Works in Your AWS Environment
Deploy the Bastion Host AMI into a public subnet within your Amazon VPC. Your private servers remain in private subnets with no direct internet access. Administrators connect to the bastion host using SSH or RDP, and from there access private instances securely. Security groups on both the bastion host and your private instances control exactly which traffic is permitted.
This architecture follows AWS best practices for secure remote administration: a single, hardened entry point with restricted access, sitting between the internet and your private resources.
Use Case: Managing a Mixed-OS Server Fleet
A development or operations team managing a fleet of Linux application servers and Windows database servers in private subnets can deploy this bastion host as their single secure gateway. Team members authenticate with SSH keys and MFA, connect to the bastion, and then reach any private instance they are authorized to access. The built-in intrusion detection automatically blocks brute-force attempts, and the lean Ubuntu base minimizes the attack surface. This approach works for teams of any size from a solo administrator managing a handful of instances to a larger operations team supporting dozens of servers across multiple private subnets.
Getting Started in Five Steps
Click Continue to Subscribe above to begin the deployment process
Configure your instance type and networking based on your requirements
Launch your server; first-run deployment completes in approximately 60 seconds
Access your bastion host using the public IP address assigned by AWS
Follow the Quick Start guide to complete initial setup and begin connecting to your private servers
Ready to Secure Your Server Access?
Stop exposing your private infrastructure to unnecessary risk. Deploy the Bastion Host on AWS today and give your team a secure, centralized gateway to every server in your environment. Click Continue to Subscribe to get started, or visit the documentation to learn more about configuration and setup.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time. Alternatively, you can pay upfront for a contract, which typically covers your anticipated usage for the contract duration. Any usage beyond contract will incur additional usage-based costs.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
If you are an AWS Free Tier customer with a free plan, you are eligible to subscribe to this offer. You can use free credits to cover the cost of eligible AWS infrastructure. See AWS Free Tier for more details. If you created an AWS account before July 15th, 2025, and qualify for the Legacy AWS Free Tier, Amazon EC2 charges for Micro instances are free for up to 750 hours per month. See Legacy AWS Free Tier for more details.
You pay by the hour for the software running on your chosen Amazon EC2 instance. The many dimensions here are simply different EC2 instance types, not feature tiers. All deliver the same bastion host (jump host) image. Your rate depends on the instance size and family you pick. The t-family options offer general-purpose burstable capacity. The m-family options balance compute and memory. The r-family options provide more memory for demanding workloads. Metal options run on dedicated hardware. Costs scale with the size and family you select, and billing stops when you stop the instance.
Top-of-mind questions for buyers
What do I actually get when I pay the hourly rate for an instance type?
You get a pre-built bastion host (jump host) image running on the Amazon EC2 instance type you pick. The hourly rate covers the software license for that image. The instance size and family you choose set the CPU and memory available for routing secure SSH access.
Am I charged when the instance is stopped or powered off?
The software rate meters running time only. When you stop the instance, the hourly software charge stops. A stopped instance may still incur underlying AWS storage fees for its attached volumes, but the license charge applies only while the instance runs.
Why are there so many instance options, and how does my rate change between them?
Each option is a different EC2 instance type, not a feature tier. All run the same bastion host image. Your rate changes with the size and family you select. The t, m, and r families differ in compute-to-memory balance. Metal options run on dedicated hardware. Larger sizes carry higher hourly rates.
www.solvedevops.com
Helpful?
Vendor refund policy
Cancel Anytime
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Updates to the latest Security Patches for Ubuntu server 26.04
Additional details
Usage instructions
Getting Started:
Provision an EC2 instance with the right capacity for your needs.
Place the instance in the right subnet making sure you have access to it. Access your Server using the IP Address issued by AWS for the initial setup.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Browser based remote access tool that provides easy access to hosts in all your VPCs, across accounts and regions. Windows desktops and Linux hosts are supported. No client software needed, a modern browser is all you need.
Browser based remote access tool that provides easy access to hosts in all your VPCs, across accounts and regions. Windows desktops and Linux hosts are supported. No client software needed, a modern browser is all you need.
This is a repackaged open-source software product wherein additional charges apply for a ready-to-run FusionPBX multi-tenant PBX with per-instance admin and database password generation, Amazon CloudWatch log and metric shipping, AWS Systems Manager agent integration, SSH hardening, and vendor support.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.