In addition to the various base features that are available out-of-the box in Enterprise Security Package (ESP), you can use the following security-related paid features that are available in ESP. For more information about ESP, visit Cloud Platform Product Guide.
This set of features uses a modern, integrated approach that allows you to manage advanced network configurations and security controls for your Cloud Platform applications. Like Shield, it provides enterprise-grade networking capabilities that enable you to implement robust security measures and maintain strict compliance requirements. This solution addresses the demanding security requirements of organizations that operate in highly regulated environments.
Advanced network isolation
Secure connectivity
Access management
Private IP range with optional VPN connection
Feature | Shield | Security features in ESP |
|---|---|---|
Network Isolation | Provides network isolation for production and non-production servers based on EC2 instances in separate VPCs. | Provides network isolation for environments based on Kubernetes infrastructure, with isolated pods in subnet. |
VPN Support | Supports VPN connectivity with IKEv1 and IKEv2. | Maintains existing VPN connections and configurations. |
IP Allowlisting for SSH access | Is available for Shield subscribers on Cloud Platform Enterprise and has a limit of 25 IP addresses or CIDR ranges. | Preserves existing security configurations. |
Infrastructure | Is based on the traditional Cloud Classic infrastructure. | Is based on the modern Cloud Next infrastructure. |
Performance | Supports standard performance. | Supports enhanced performance and scalability. |
Migration Path | - | Has seamless migration path to the Cloud Next infrastructure. |
Private outward connections or private egress facilitates secure outbound connections from customer applications to internal systems. This feature ensures that outbound traffic is securely managed. This allows applications to communicate with backend systems such as APIs and other internal resources.
Through a private outbound connection, you can ensure that your outbound traffic is securely managed and isolated, which provides peace of mind and compliance with security standards.
To use Cloud Platform with VPN:
Acquia provisions and configures a dedicated network for your applications. In addition, Acquia provides you with the Internet Protocol Security (IPSec)/ Internet Key Exchange information so that you can properly configure your VPN.
In order for Acquia to be able to configure the security features in ESP, you must provide the following information:
To connect to Cloud Platform with VPN, your network must use a VPN (a secure Internet gateway) using IPsec. The gateway devices are compatible with Cloud Platform with VPN. Other devices may work, but Acquia does not support them.
You must properly configure your network’s gateway to connect to Cloud Platform with VPN. After you provision your dedicated section, Acquia will provide you with configuration and VPN details. You will receive the Pre-Shared Key (PSK) information that is needed in order to properly configure your VPN. Use SSH to access information stored in a secure location.
Cloud Platform uses Dead Peer Detection (DPD), exchanging UDP packets between VPN peers to ensure that both ends are available. If no traffic crosses the VPN tunnel in ten seconds, Cloud Platform sends a request. Three successive requests without a response will cause Cloud Platform to close the VPN tunnel.
After Acquia provisions this feature for your infrastructure and provides connection information to you, it is your responsibility to configure your VPN device, establish the secure tunnel, and keep the network connection alive.
You must also confirm that your secondary tunnel is configured properly in case your primary tunnel becomes unavailable. When properly configured, your gateway must fail over to the secondary tunnel in your tunnel pair, if needed.
If you are already utilizing AWS infrastructure and have existing AWS clusters that host your other applications, you can use a VPC Peer connection instead of a VPN connection.
To use Cloud Platform with VPC Peering:
In order for Acquia to be able to configure the security features in ESP, you must provide the following information:
If this content did not answer your questions, try searching or contacting our support team for further assistance.
Advanced network isolation
Secure connectivity
Access management
Private IP range with optional VPN connection
Feature | Shield | Security features in ESP |
|---|---|---|
Network Isolation | Provides network isolation for production and non-production servers based on EC2 instances in separate VPCs. | Provides network isolation for environments based on Kubernetes infrastructure, with isolated pods in subnet. |
VPN Support | Supports VPN connectivity with IKEv1 and IKEv2. | Maintains existing VPN connections and configurations. |
IP Allowlisting for SSH access | Is available for Shield subscribers on Cloud Platform Enterprise and has a limit of 25 IP addresses or CIDR ranges. | Preserves existing security configurations. |
Infrastructure | Is based on the traditional Cloud Classic infrastructure. | Is based on the modern Cloud Next infrastructure. |
Performance | Supports standard performance. | Supports enhanced performance and scalability. |
Migration Path | - | Has seamless migration path to the Cloud Next infrastructure. |
Private outward connections or private egress facilitates secure outbound connections from customer applications to internal systems. This feature ensures that outbound traffic is securely managed. This allows applications to communicate with backend systems such as APIs and other internal resources.
Through a private outbound connection, you can ensure that your outbound traffic is securely managed and isolated, which provides peace of mind and compliance with security standards.
To use Cloud Platform with VPN:
Acquia provisions and configures a dedicated network for your applications. In addition, Acquia provides you with the Internet Protocol Security (IPSec)/ Internet Key Exchange information so that you can properly configure your VPN.
In order for Acquia to be able to configure the security features in ESP, you must provide the following information:
To connect to Cloud Platform with VPN, your network must use a VPN (a secure Internet gateway) using IPsec. The gateway devices are compatible with Cloud Platform with VPN. Other devices may work, but Acquia does not support them.
You must properly configure your network’s gateway to connect to Cloud Platform with VPN. After you provision your dedicated section, Acquia will provide you with configuration and VPN details. You will receive the Pre-Shared Key (PSK) information that is needed in order to properly configure your VPN. Use SSH to access information stored in a secure location.
Cloud Platform uses Dead Peer Detection (DPD), exchanging UDP packets between VPN peers to ensure that both ends are available. If no traffic crosses the VPN tunnel in ten seconds, Cloud Platform sends a request. Three successive requests without a response will cause Cloud Platform to close the VPN tunnel.
After Acquia provisions this feature for your infrastructure and provides connection information to you, it is your responsibility to configure your VPN device, establish the secure tunnel, and keep the network connection alive.
You must also confirm that your secondary tunnel is configured properly in case your primary tunnel becomes unavailable. When properly configured, your gateway must fail over to the secondary tunnel in your tunnel pair, if needed.
If you are already utilizing AWS infrastructure and have existing AWS clusters that host your other applications, you can use a VPC Peer connection instead of a VPN connection.
To use Cloud Platform with VPC Peering:
In order for Acquia to be able to configure the security features in ESP, you must provide the following information:
If this content did not answer your questions, try searching or contacting our support team for further assistance.