The Hillstone CloudEdge Virtual-Firewall (PAYG) supports 2-4-core EC2 instance providing high performance. The Hillstone Virtual Firewall features most of the networking services common to Hillstone's hardware based appliances and is an ideal solution for protecting network resources within AWS.
The Hillstone CloudEdge Virtual-Firewall (PAYG) provides flexible performance tiers across VM01/02/04/08, automatically scaling based on your selected cloud instance and subscription. It supports 2-4-core EC2 instance providing high performance. The Hillstone Virtual Firewall allows you to provision firewall security whenever and wherever it is needed. It features most of the networking services common to Hillstone's hardware based appliances and is an ideal solution for protecting network resources within AWS. It offers enhanced access control, Virtual Private Network (VPN), L2-L7 attack protection, and server load balancing for AWS users. With the addition of the virtual firewall, Hillstone offers greater choice and exibility by providing the ability to deploy a mix of hardware and virtual appliances operating together. In 5.5R10, VM01 supports up to 200k concurrent sessions, max 100 IPSec VPN tunnels and max 100 SSL VPN users; VM02 supports up to 500k concurrent sessions, max 500 IPSec VPN tunnels and max 500 SSL VPN users; VM04 supports up to 5M concurrent sessions, max 10000 IPSec VPN tunnels and max 2000 SSL VPN users; VM08 supports up to 10M concurrent sessions, max 20000 IPSec VPN tunnels and max 4000 SSL VPN users. For detail, please refer the datasheet in Additional Resources. For more details about Hillstone CloudEdge usage instructions including deployment guide or WebUI user guide, please refer to: https://docs.hillstonenet.com/contents.html?cid=328&selected=0&is_small=1
Highlights
The CloudEdge enables north-south traffic inspection to provide the VPC network with dedicated security isolation via policy control, as well as granular access control, QoS, VPN,IPS and server load balancing to guarantee business continuity
The CloudEdge offers IPSec VPN and SCVPN for endpoint and hybrid-cloud, standards-based site-to-site VPN connections are established between the corporate local network, branches and your AWS virtual service
The CloudEdge provides server load balancing, helping enterprises establish an EC2 cluster on AWS traffic can be assigned equally to different EC2 instances, all providing the same service.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
You pay by the hour for this virtual next-generation firewall, with billing tied to the AWS instance type you run it on. Two options are available: c5a.xlarge and c5.xlarge. Both are hourly usage-based dimensions, so your cost scales with how many hours each instance runs. The two dimensions reflect different underlying compute instance families rather than separate feature tiers. This pay-as-you-go structure lets you scale the firewall up or down to match your workload demand.
Top-of-mind questions for buyers
What difference between the c5a.xlarge and c5.xlarge dimensions affects my bill?
Both dimensions run the same firewall software billed per hour. The difference is the underlying AWS compute instance family you choose. Each instance type carries its own hourly rate. Your choice sets which rate applies, but the firewall capabilities remain the same across both.
Am I charged when the firewall instance is stopped or powered off?
Hourly software charges accrue only while the instance runs. A fully stopped instance does not accrue firewall software charges. You may still incur underlying AWS storage fees for the stopped instance, but the software license meters running hours only.
Can I scale this firewall up or down as my workload changes?
Yes. This usage-based model supports dynamic scale-up and scale-down. You launch more instances when demand rises and shut them down when it falls. You pay only for the hours each instance runs, so cost tracks your active workload.
www.hillstonenet.com
Helpful?
Vendor refund policy
N/A
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Please allow 24 hours You can depend on Hillstone Networks remote support services for expert, timely technical resources to help you maintain network security and protect your business 24x7. In addition to real-time online support, you may access our experienced, certified engineers through toll-free hotlines.For details, please contact Hillstone at +1 800-930-6707.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
The Hillstone CloudEdge Virtual-Firewall (BYOL) supports 2-4-core EC2 instance providing high performance. The Hillstone Virtual Firewall features most of the networking services common to Hillstone's hardware based appliances and is an ideal solution for protecting network resources within AWS.
Ideal for remote worker and multi-tenant environments, Secure Firewall ASA Virtual provides scalable VPN options including remote access, site-to-site, clientless, and more. Experience Cisco's industry-leading firewall to protect your cloud resources.
Protect AWS workloads, VDIs, and user traffic with AI/ML-powered virtual firewall from Palo Alto Networks. This listing includes VM-Series virtual firewall, Palo Alto Networks flagship - Advanced Threat Prevention security service and 24x7 premium technical support
Protect your dynamic cloud environments with consistent security, superior visibility, and advanced threat defense such as application visibility and control, deep packet inspection, IPS, malware defense, and URL filtering - powered by Cisco Talos® Threat Intelligence. Achieve deeper visibility into QUIC and TLS 1.3 traffic without breaking Layer 7 policies.
Consistent cloud and on-prem security has protected workloads and provides granular traffic control
Reviewed on Aug 25, 2026
Review provided by PeerSpot
What is our primary use case?
We deploy Hillstone CloudEdge Virtual-Firewall in AWS to protect workloads hosted inside our VPC. We use it to inspect north-south traffic, enforce access-control policies, secure communication between environments, and protect internet-facing applications and servers. Our main requirements include firewall policy enforcement, VPN connectivity, intrusion prevention, application control, and improved visibility into network traffic. The Hillstone model is suitable for our cloud environment because it gives us flexibility.
How has it helped my organization?
CloudEdge has helped us apply consistent security controls to our AWS workloads with our on-premises workloads. It provides an additional security layer beyond basic security groups and network ACLs. This allows us to inspect traffic more closely and enforce more detailed policies.
What is most valuable?
The most valuable aspect is the combination of traditional firewall functionality with cloud deployment flexibility. Important features include granular access control, IPsec and SSL VPN, intrusion prevention, antivirus, application control, traffic monitoring, and attack protection. The interface is relatively straightforward for administrators who already have firewall experience. The firewall integrates well into an AWS VPC architecture and provides useful control over traffic entering and leaving protected networks. The CloudEdge uses the same StoneOS platform as Hillstone's physical security appliances. This helps maintain a consistent configuration and management experience across physical and virtual environments.
What needs improvement?
Additional automation resources for AWS would also be helpful. More comprehensive CloudFormation or Terraform examples, deployment templates, and guidance for high-availability architectures could make larger implementations easier.
For how long have I used the solution?
I have used the solution for three years.
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?