Shield provides isolated networks for Cloud Platform applications. Subscriber deployments in an isolated network environment are separated from other subscriber deployments at the network level.
Benefits of using Shield
Shield combines the benefits of Cloud Platform-as-a-service with extra security benefits and capabilities, giving you a greater degree of isolation for your Cloud Platform instances.
Shield includes the following product features:
- Shield access management: Provides self-service IP allowlisting for occasions when you must manage SSH access to the environments in your subscription. This feature is available only for Cloud Platform subscribers and not for Site Factory.
Private IP range with optional VPN connection: Adds an optional Virtual Private Network (VPN) hosted by Cloud Platform to connect between Cloud Platform and your private network. The VPN connection ensures you have secure bi-directional interaction between your websites and your internal IT systems (such as a CRM). Packaged in the price of Shield is the VPN configured to connect Cloud Platform with one subscriber-defined gateway device point. Added virtual private cloud (VPC) peering connections are available for a fee.
To enable the VPN, you must first buy a subscription to Cloud Platform.
If you change endpoints during the Subscription Term, you will incur added fees of $250 per hour of work. For Acquia to enable the VPN connection, you must meet the technical requirements described in the Amazon VPC FAQs.
- AWS VPC Peering Connection: Enables a VPC peering connection between your Shield VPC and another AWS VPC. You can enable added VPC peering connections for a fee.
Using Shield
To use Shield, you must buy Shield with your Cloud Platform or Site Factory subscription. Acquia provisions your servers in your dedicated network.
Initiating your Shield tunnel
After Acquia provisions Shield and provides connection information to you, it’s your responsibility to configure your VPN device, establish the secure tunnel, and keep the network connection alive.
You must also confirm your secondary tunnel is configured properly in case your primary tunnel becomes unavailable. When properly configured, your gateway must fail over to the secondary tunnel in your Shield tunnel pair, if needed.
Changing your IP addresses
Moving an existing application hosted by Cloud Platform or Site Factory to Shield with VPN changes your IP address. You cannot move IP addresses into or out of a VPC. However, EIPs are retained if VPC provisioning is in the same region.
As a result, when you configure your application in Shield with VPN, you must point the DNS records of your application to the new IP address in the VPC. For more information, see Configuring DNS records for your application.
Watch our video for an overview of Acquia's Product Resources and Enablement