#AmazonVpc
AWS Weekly Roundup: Amazon Q Developer, AWS Step Functions, AWS Cloud Club Captain deadline, and more (September 22, 2025)

Three weeks ago, I published a post about the new AWS Region in New Zealand (ap-sou...

#AWS #AmazonBedrock #AmazonQDeveloper #AmazonVpc #AwsStepFunctions #News #WeekInReview
AWS Weekly Roundup: Amazon Q Developer, AWS Step Functions, AWS Cloud Club Captain deadline, and more (September 22, 2025)
Three weeks ago, I published a post about the new AWS Region in New Zealand (ap-southeast-6). This led to an incredible opportunity to visit New Zealand, where I met passionate builders and presented at several events including Serverless and Platform Engineering meetup, AWS Tools and Programming meetup, AWS Cloud Clubs in Auckland, and AWS Community […]
aws.amazon.com
September 22, 2025 at 5:05 PM
Amazon VPC IPAM automates prefix list updates

Today, AWS announced the ability for Amazon VPC IP Address Manager (IPAM) to automate prefix lists updates with prefix list resolver (PLR). This feature allows network administrators to automatically update prefix lists based on th...

#AWS #AmazonVpc
Amazon VPC IPAM automates prefix list updates
Today, AWS announced the ability for Amazon VPC IP Address Manager (IPAM) to automate prefix lists updates with prefix list resolver (PLR). This feature allows network administrators to automatically update prefix lists based on their business logic in IPAM improving their operational posture and reducing overhead. Using IPAM PLR, you can define business rules for synchronizing prefix lists with IP address ranges from various resources, such as VPCs, subnets and IPAM pools. These prefix lists can then be referenced in resources such as route tables and security groups across your AWS environment, based on your connectivity requirements. Previously, you had to manually update your prefix lists to add or remove IP address ranges based on changes to your AWS environment. This was operationally complex and error prone. IPAM PLR automates prefix list updates requiring no manual intervention, improving your operational posture. This feature is now available in all https://aws.amazon.com/about-aws/global-infrastructure/regional-product-services/ where Amazon VPC IPAM is supported, including AWS China Regions, and AWS GovCloud (US) Regions. To learn more about this feature, view the https://docs.aws.amazon.com/vpc/latest/ipam/automate-prefix-list-updates.html. For details on pricing, refer to the IPAM tab on the https://aws.amazon.com/vpc/pricing/.
aws.amazon.com
October 31, 2025 at 10:05 PM
AWS Network Firewall now supports IPv6 Service Endpoints

AWS Network Firewall introduces dual stack support for Network Firewall management API, enabling you to connect using Internet Protocol Version 6 (IPv6), Internet Protocol Version 4 (IP...

#AWS #AmazonVpc #AwsNetworkFirewall #AwsGovcloudUs
AWS Network Firewall now supports IPv6 Service Endpoints
AWS Network Firewall introduces dual stack support for Network Firewall management API, enabling you to connect using Internet Protocol Version 6 (IPv6), Internet Protocol Version 4 (IPv4), or dual stack clients. Dual stack support is also available when the AWS Network Firewall management API endpoint is privately accessed from your Amazon Virtual Private Cloud (VPC) using AWS https://aws.amazon.com/about-aws/whats-new/2022/12/amazon-eks-supports-aws-privatelink/. Dual stack endpoints are made available on a new AWS DNS domain name. The existing AWS Network Firewall management API endpoints are maintained for backwards compatibility reasons. AWS Network Firewall is a managed firewall service that is easy to deploy. The service automatically scales with network traffic volume to provide high-availability protections without the need to set up and maintain the underlying infrastructure. With simultaneous support for both IPv4 and IPv6 clients on AWS Network Firewall endpoints, you are able to gradually transition from IPv4 to IPv6 based systems and applications, without needing to switch all over at once. There is no additional charge when you connect to AWS Network Firewall endpoints using Internet Protocol Version 6 (IPv6) clients. To see which regions AWS Network Firewall is available in, visit the https://aws.amazon.com/about-aws/global-infrastructure/regional-product-services/. For more information, please see the AWS Network Firewall https://aws.amazon.com/network-firewall/ and the service https://docs.aws.amazon.com/network-firewall/latest/developerguide/.  
aws.amazon.com
January 19, 2025 at 11:05 PM
🆕 Amazon CloudFront supports BYOIP for IPv6 via VPC IPAM, offering dedicated IPv4 and IPv6 address pools for Anycast Static IPs, simplifying IP management. Available in most AWS regions, excluding some in the Middle East and China. See Amazon VPC Pricing Page for…

#AWS #AmazonVpc #AmazonCloudfront
Amazon CloudFront now supports BYOIP for IPv6 through VPC IPAM integration
Amazon CloudFront now supports bringing your own IPv6 addresses (BYOIP) for Anycast Static IPs via VPC IP Address Manager (IPAM). This capability enables network administrators to use their own public IPv4 and IPv6 address pools with CloudFront distributions, simplifying IP address management across AWS's global infrastructure. CloudFront typically uses rotating IP addresses to serve traffic. CloudFront Anycast Static IPs enables customers to provide a dedicated list of IP addresses to partners and customers, enhancing security and simplifying network management. Previously, customers implementing BYOIP with Anycast Static IPs could only bring their own IPv4 addresses (/24 blocks). With IPAM's unified interface, customers can now create dedicated IP address pools using BYOIP for IPv4 (/24) and IPv6 (/48), and assign them to CloudFront Anycast Static IP lists in a dual-stack configuration. Customers do not need to change the existing IP address space for their applications when they migrate to CloudFront, thus maintaining existing allow-lists and branding for both IPv4 and IPv6 clients.   The feature is available within Amazon VPC IPAM in all commercial AWS Regions except the Middle East (Bahrain), Middle East (UAE), AWS GovCloud (US) Regions, and China (Beijing, operated by Sinnet) and China (Ningxia, operated by NWCD). To learn more about CloudFront BYOIP feature, view the BYOIP CloudFront documentation. For details on pricing, refer to the IPAM tab on the Amazon VPC Pricing Page.
aws.amazon.com
March 31, 2026 at 10:12 PM
AWS Transfer Family SFTP connectors now support VPC-based connectivity

AWS Transfer Family SFTP connectors now support VPC-based connectivity, allowing secure file transfers between Amazon S3 and remot...

#AWS #AmazonVpc #AwsTransferFamily #AwsTransferForSftp #Migration&TransferServices #Storage
AWS Transfer Family SFTP connectors now support VPC-based connectivity
AWS Transfer Family SFTP connectors now support VPC-based connectivity, allowing secure file transfers between Amazon S3 and remote SFTP servers through your existing VPC infrastructure without exposing endpoints to the internet.
aws.amazon.com
October 14, 2025 at 8:05 PM
AWS Transfer Family SFTP connectors now support VPC-based connectivity

AWS Transfer Family SFTP connectors now support VPC-based connectivity, allowing secure file transfers between Amazon S3 and remot...

#AWS #AmazonVpc #AwsTransferFamily #AwsTransferForSftp #Migration&TransferServices #Storage
AWS Transfer Family SFTP connectors now support VPC-based connectivity
AWS Transfer Family SFTP connectors now support VPC-based connectivity, allowing secure file transfers between Amazon S3 and remote SFTP servers through your existing VPC infrastructure without exposing endpoints to the internet.
aws.amazon.com
November 13, 2025 at 9:05 PM
Introducing VPC encryption controls: Enforce encryption in transit within and across VPCs in a Region

AWS announces VPC encryption controls, a new capability that helps organizations audit and enforce encryption in transit for all traffic within an...

#AWS #AmazonVpc #Announcements #Launch #News
Introducing VPC encryption controls: Enforce encryption in transit within and across VPCs in a Region
AWS announces VPC encryption controls, a new capability that helps organizations audit and enforce encryption in transit for all traffic within and across VPCs in a Region, simplifying compliance with regulatory frameworks like HIPAA, PCI DSS, and FedRAMP through automated monitoring and enforcement modes.
aws.amazon.com
November 21, 2025 at 5:05 PM
🆕 AWS supports VPC endpoints for CloudWatch, securing traffic within its network for private observability management across accounts, available in all commercial regions and AWS GovCloud.

#AWS #AmazonCloudwatch #AmazonVpc #AwsGovcloudUs
Amazon CloudWatch Observability Access Manager Now Supports VPC Endpoints
AWS announces VPC endpoints for Amazon CloudWatch Observability Access Manager (OAM). CloudWatch OAM enables you to programmatically manage cross-account observability settings within a region. The new VPC endpoints enhance your security posture by keeping traffic between your VPC and CloudWatch OAM within the AWS network, eliminating the need to traverse the public internet. You can use Observability Access Manager to create and manage links between source accounts and monitoring accounts, enabling you to monitor and troubleshoot applications that span multiple accounts within a Region. With the new VPC endpoints, you can establish secure, private, and reliable connections between your VPC and CloudWatch Observability Access Manager. This allows you to maintain private connectivity while managing cross-account observability links and sinks, even from VPCs without internet access. This feature supports both IPv4 and IPv6 addressing, and you can use AWS PrivateLink's built-in security controls—like security groups and VPC endpoint policies—to help secure access to your observability resources. CloudWatch Observability Access Manager VPC endpoints are now available in all commercial AWS regions, the AWS GovCloud (US) Regions, and the China Regions. To start using VPC endpoints for CloudWatch Observability Access Manager, refer to CloudWatch OAM endpoints for a list of supported Regional endpoints. To learn more about AWS PrivateLink, see accessing AWS services through AWS PrivateLink.
aws.amazon.com
September 11, 2025 at 5:40 PM
🆕 AWS Network Firewall now supports IPv6 Service Endpoints

#AWS #AmazonVpc #AwsNetworkFirewall #AwsGovcloudUs
AWS Network Firewall now supports IPv6 Service Endpoints
AWS Network Firewall introduces dual stack support for Network Firewall management API, enabling you to connect using Internet Protocol Version 6 (IPv6), Internet Protocol Version 4 (IPv4), or dual stack clients. Dual stack support is also available when the AWS Network Firewall management API endpoint is privately accessed from your Amazon Virtual Private Cloud (VPC) using AWS PrivateLink. Dual stack endpoints are made available on a new AWS DNS domain name. The existing AWS Network Firewall management API endpoints are maintained for backwards compatibility reasons. AWS Network Firewall is a managed firewall service that is easy to deploy. The service automatically scales with network traffic volume to provide high-availability protections without the need to set up and maintain the underlying infrastructure. With simultaneous support for both IPv4 and IPv6 clients on AWS Network Firewall endpoints, you are able to gradually transition from IPv4 to IPv6 based systems and applications, without needing to switch all over at once. There is no additional charge when you connect to AWS Network Firewall endpoints using Internet Protocol Version 6 (IPv6) clients. To see which regions AWS Network Firewall is available in, visit the AWS Region Table. For more information, please see the AWS Network Firewall product page and the service documentation.
aws.amazon.com
December 20, 2024 at 9:23 PM
🆕 VPC Lattice now includes TCP support with VPC Resources

#AWS #AwsPrivatelink #AmazonVpc
VPC Lattice now includes TCP support with VPC Resources
With the launch of VPC Resources for Amazon VPC Lattice, you can now access all of your application dependencies through a VPC Lattice service network. You're able to connect to your application dependencies hosted in different VPCs, accounts, and on-premises using additional protocols, including TLS, HTTP, HTTPS, and now TCP. This new feature expands upon the existing HTTP-based services support, enabling you to share a wider range of resources across your organization. With VPC Resource support, you can add your TCP resources, such as Amazon RDS databases, custom DNS, or IP endpoints, to a VPC Lattice service network. Now, you can share and connect to all your application dependencies, such as HTTP APIs and TCP databases, across thousands of VPCs, simplifying network management and providing centralized visibility with built-in access controls. VPC Resources are generally available with VPC Lattice in Africa (Cape Town), Asia Pacific (Mumbai), Asia Pacific (Singapore), Asia Pacific (Sydney), Europe (Frankfurt), Europe (Ireland), Europe (Paris), Europe (Stockholm), Middle East (Bahrain), South America (Sao Paulo), US East (N. Virginia), US East (Ohio), US West (Oregon). To get started, read the VPC Resources launch blog, architecture blog, and VPC Lattice User Guide. Learn more about VPC Lattice, visit Amazon VPC Lattice Getting Started.
aws.amazon.com
December 3, 2024 at 3:23 AM
AWS Weekly Roundup: Amazon Q Developer, AWS Step Functions, AWS Cloud Club Captain deadline, and more (September 22, 2025)

Three weeks ago, I published a post about the new AWS Region in New Zealand (ap-sou...

#AWS #AmazonBedrock #AmazonQDeveloper #AmazonVpc #AwsStepFunctions #News #WeekInReview
AWS Weekly Roundup: Amazon Q Developer, AWS Step Functions, AWS Cloud Club Captain deadline, and more (September 22, 2025)
Three weeks ago, I published a post about the new AWS Region in New Zealand (ap-southeast-6). This led to an incredible opportunity to visit New Zealand, where I met passionate builders and presented at several events including Serverless and Platform Engineering meetup, AWS Tools and Programming meetup, AWS Cloud Clubs in Auckland, and AWS Community […]
aws.amazon.com
October 22, 2025 at 6:05 PM
Amazon VPC Route Server announces logging enhancements

Amazon VPC Route Server enhances connectivity monitoring and logging with new network metrics. These metrics allow customers to proactively monitor network health, troubleshoot network issues and gain visibility into route...

#AWS #AmazonVpc
Amazon VPC Route Server announces logging enhancements
Amazon VPC Route Server enhances connectivity monitoring and logging with new network metrics. These metrics allow customers to proactively monitor network health, troubleshoot network issues and gain visibility into route propagation and peer connectivity. Previously, customers would manually track Border Gateway Protocol (BGP) and Bidirectional Forwarding Detection (BFD) session changes and often required AWS Support assistance for network troubleshooting. With these new logging capabilities, customers can independently monitor and diagnose network connectivity issues, leading to faster resolution times and improved network visibility. The enhancement offers real-time monitoring of BGP and BFD session states, historical peer-to-peer session data logging and flexible log delivery options through CloudWatch, S3, Data Firehose or AWS CLI. Enhanced logging for VPC Route Server is available in all AWS commercial regions where VPC Route Server is supported. Data charges for vended logs will apply for Amazon CloudWatch, Amazon S3, and Amazon Data Firehose. To learn more about this feature, please refer to our https://docs.aws.amazon.com/vpc/latest/userguide/route-server-peer-logging.html.  
aws.amazon.com
June 4, 2025 at 5:05 PM
🆕 AWS extends Traffic Mirroring support to all Nitro v4 instances, enabling network traffic replication for security and monitoring in Amazon VPC. Full list in documentation.

#AWS #AmazonVirtualPrivateCloud #AmazonVpc #AwsGovcloudUs
AWS extends Traffic Mirroring support on new instance types
Amazon Virtual Private Cloud (Amazon VPC) Traffic Mirroring is now supported on additional instance types. Amazon VPC Traffic Mirroring allows you to replicate the network traffic from EC2 instances within your VPC to security and monitoring appliances for use cases such as content inspection, threat monitoring, and troubleshooting. With this release, VPC Traffic Mirroring can be enabled on all Nitro v4 instances. You can see the complete list of instances that support VPC Traffic Mirroring in our documentation. You can see the complete list of instances built on different Nitro system versions in our AWS Nitro Systems documentation. VPC Traffic Mirroring is supported on these additional instance types in all regions. To learn more about VPC Traffic Mirroring, please visit the VPC Traffic Mirroring documentation.
aws.amazon.com
August 28, 2025 at 7:40 PM
Amazon CloudWatch Observability Access Manager Now Supports VPC Endpoints

AWS announces VPC endpoints for Amazon CloudWatch Observability Access Manager (OAM). CloudWatch OAM enables you to programmatically manage cross-account observability se...

#AWS #AmazonCloudwatch #AmazonVpc #AwsGovcloudUs
Amazon CloudWatch Observability Access Manager Now Supports VPC Endpoints
AWS announces VPC endpoints for Amazon CloudWatch Observability Access Manager (OAM). CloudWatch OAM enables you to programmatically manage cross-account observability settings within a region. The new VPC endpoints enhance your security posture by keeping traffic between your VPC and CloudWatch OAM within the AWS network, eliminating the need to traverse the public internet. You can use Observability Access Manager to create and manage links between source accounts and monitoring accounts, enabling you to monitor and troubleshoot applications that span multiple accounts within a Region. With the new VPC endpoints, you can establish secure, private, and reliable connections between your VPC and CloudWatch Observability Access Manager. This allows you to maintain private connectivity while managing cross-account observability links and sinks, even from VPCs without internet access. This feature supports both IPv4 and IPv6 addressing, and you can use AWS PrivateLink's built-in security controls—like security groups and VPC endpoint policies—to help secure access to your observability resources. CloudWatch Observability Access Manager VPC endpoints are now available in all https://aws.amazon.com/about-aws/global-infrastructure/regions_az/, the AWS GovCloud (US) Regions, and the China Regions. To start using VPC endpoints for CloudWatch Observability Access Manager, refer to https://docs.aws.amazon.com/general/latest/gr/cloudwatchoam.html for a list of supported Regional endpoints. To learn more about AWS PrivateLink, see https://docs.aws.amazon.com/vpc/latest/privatelink/privatelink-access-aws-services.html.
aws.amazon.com
September 11, 2025 at 6:05 PM
🆕 AWS announced Amazon VPC IPAM's prefix list resolver to automate updates, reducing manual overhead and improving operational efficiency. Now available in all supported regions, it syncs prefix lists based on business rules, eliminating manual updates.

#AWS #AmazonVpc
Amazon VPC IPAM automates prefix list updates
Today, AWS announced the ability for Amazon VPC IP Address Manager (IPAM) to automate prefix lists updates with prefix list resolver (PLR). This feature allows network administrators to automatically update prefix lists based on their business logic in IPAM improving their operational posture and reducing overhead. Using IPAM PLR, you can define business rules for synchronizing prefix lists with IP address ranges from various resources, such as VPCs, subnets and IPAM pools. These prefix lists can then be referenced in resources such as route tables and security groups across your AWS environment, based on your connectivity requirements. Previously, you had to manually update your prefix lists to add or remove IP address ranges based on changes to your AWS environment. This was operationally complex and error prone. IPAM PLR automates prefix list updates requiring no manual intervention, improving your operational posture. This feature is now available in all AWS Regions where Amazon VPC IPAM is supported, including AWS China Regions, and AWS GovCloud (US) Regions. To learn more about this feature, view the AWS IPAM documentation. For details on pricing, refer to the IPAM tab on the Amazon VPC Pricing Page.
aws.amazon.com
October 31, 2025 at 9:40 PM
Amazon VPC IPAM now supports tags on IPAM pool allocations

Amazon VPC IP Address Manager (IPAM) now supports tags on IPAM pool allocations, enabling customers to organize, govern, and control access to individual IP address allocations using the same tagging workflows they use a...

#AWS #AmazonVpc
Amazon VPC IPAM now supports tags on IPAM pool allocations
Amazon VPC IP Address Manager (IPAM) now supports tags on IPAM pool allocations, enabling customers to organize, govern, and control access to individual IP address allocations using the same tagging workflows they use across other AWS resources. Amazon VPC IP Address Manager (IPAM) helps customers plan, track, and monitor IP addresses across their AWS environments. With this launch, customers can tag allocations at creation time or add tags to existing allocations. These tags can be referenced in AWS Identity and Access Management and Service Control Policies, enabling centralized governance over IP address usage at scale. For example, a network administrator can tag allocations by environment and enforce an IAM policy that allows only the production networking role to allocate from the pool, while development teams are restricted to development pools. Customers can also search and filter allocations by tag across all IPAM pools, making it faster to locate specific IP address ranges in large, multi-account environments. This feature is available in all AWS Regions where IPAM is available at no additional cost. To learn more, see the https://docs.aws.amazon.com/vpc/latest/ipam/allocate-cidrs-ipam.html. To get started with IPAM, visit the https://console.aws.amazon.com/ipam/.
aws.amazon.com
May 26, 2026 at 8:05 PM
Amazon VPC Reachability Analyzer and Amazon VPC Network Access Analyzer are now available in AWS GovCloud (US) Regions

With this launch, Amazon https://docs.aws.amazon.com/vpc/latest/reachability/getting-started.html and Amazon VPC https://docs.aws.amazon.com/vpc/latest/networ...

#AWS #AmazonVpc
Amazon VPC Reachability Analyzer and Amazon VPC Network Access Analyzer are now available in AWS GovCloud (US) Regions
With this launch, Amazon https://docs.aws.amazon.com/vpc/latest/reachability/getting-started.html and Amazon VPC https://docs.aws.amazon.com/vpc/latest/network-access-analyzer/what-is-network-access-analyzer.html are now available in both AWS GovCloud (US-West) and AWS GovCloud (US-East) Regions. VPC Reachability Analyzer allows you to diagnose network reachability between a source resource and a destination resource in your virtual private clouds (VPCs) by analyzing your network configurations. For example, Reachability Analyzer can help you identify a missing route table entry in your VPC route table that could be blocking network reachability between an EC2 instance in Account A that is not able to connect to another EC2 instance in Account B in your AWS Organization. VPC Network Access Analyzer allows you to identify unintended network access to your AWS resources, helping you meet your security and compliance guidelines. For example, you can create a scope to verify that all paths from your web-applications to the internet, traverse the firewall, and detect any paths that bypass the firewall. For more information, visit documentation for https://docs.aws.amazon.com/vpc/latest/reachability/what-is-reachability-analyzer.html and https://docs.aws.amazon.com/vpc/latest/network-access-analyzer/what-is-network-access-analyzer.html For pricing, refer to the Network Analysis tab on the https://aws.amazon.com/vpc/pricing/. 
aws.amazon.comabout-aws
October 24, 2025 at 10:05 PM
Amazon CloudFront integrates with VPC IPAM to support BYOIP

Amazon CloudFront now supports bringing your own IP addresses (BYOIP) for Anycast Static IPs via VPC IP Address Manager (IPAM). This capability enables network administrators to use their own public ...

#AWS #AmazonVpc #AmazonCloudfront
Amazon CloudFront integrates with VPC IPAM to support BYOIP
Amazon CloudFront now supports bringing your own IP addresses (BYOIP) for Anycast Static IPs via VPC IP Address Manager (IPAM). This capability enables network administrators to use their own public IPv4 address pools with CloudFront distributions, simplifying IP address management across AWS's global infrastructure. CloudFront typically uses rotating IP addresses to serve traffic. CloudFront Anycast Static IPs enables customers to provide a dedicated list of IP addresses to partners and customers, enhancing security and simplifying network management. Previously, customers implementing Anycast Static IPs received AWS-provided static IP addresses for their workloads. With IPAM's unified interface, customers can now create dedicated IP address pools using BYOIP and assign them to CloudFront Anycast Static IP lists. Customers do not need to change the existing IP address space for their applications when they migrate to CloudFront, thus maintaining existing allow-lists and branding. The feature is available within Amazon VPC IPAM in all commercial AWS Regions, excluding the AWS GovCloud (US) Regions, and China (Beijing, operated by Sinnet) and China (Ningxia, operated by NWCD). To learn more about CloudFront BYOIP feature, view the https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/bring-your-own-ip-address-using-ipam.html. For details on pricing, refer to the IPAM tab on the https://aws.amazon.com/vpc/pricing/.
aws.amazon.com
November 24, 2025 at 10:05 PM
🆕 Amazon VPC IPAM now supports tags on IPAM pool allocations for better organization, governance, and access control of IP addresses, enhancing centralized management across large, multi-account environments. Available at no extra cost in all IPAM-enabled regions.

#AWS #AmazonVpc
Amazon VPC IPAM now supports tags on IPAM pool allocations
Amazon VPC IP Address Manager (IPAM) now supports tags on IPAM pool allocations, enabling customers to organize, govern, and control access to individual IP address allocations using the same tagging workflows they use across other AWS resources. Amazon VPC IP Address Manager (IPAM) helps customers plan, track, and monitor IP addresses across their AWS environments. With this launch, customers can tag allocations at creation time or add tags to existing allocations. These tags can be referenced in AWS Identity and Access Management and Service Control Policies, enabling centralized governance over IP address usage at scale. For example, a network administrator can tag allocations by environment and enforce an IAM policy that allows only the production networking role to allocate from the pool, while development teams are restricted to development pools. Customers can also search and filter allocations by tag across all IPAM pools, making it faster to locate specific IP address ranges in large, multi-account environments. This feature is available in all AWS Regions where IPAM is available at no additional cost. To learn more, see the IPAM User Guide. To get started with IPAM, visit the IPAM console.
aws.amazon.com
May 26, 2026 at 8:10 PM
Amazon VPC IPAM now supports policies to enforce IP allocation strategy

Amazon Virtual Private Cloud (VPC) IP Address Manager (IPAM) supports policies to centrally configure and enforce your desired IP allocation strategy. This ensures resources launch with publ...

#AWS #AmazonVpc #AwsGovcloudUs
Amazon VPC IPAM now supports policies to enforce IP allocation strategy
Amazon Virtual Private Cloud (VPC) IP Address Manager (IPAM) supports policies to centrally configure and enforce your desired IP allocation strategy. This ensures resources launch with public IPv4 addresses from specific IPAM pools, improving operational posture, and simplifying network and security management. Using IPAM policies, the IP administrator can centrally define public IP allocation rules for AWS resources, such as Network Address Translation (NAT) Gateways when used in regional availability mode and Elastic IP addresses. The IP allocation policy configured centrally cannot be superseded by individual application teams, ensuring compliance at all times. Before this feature, IP administrator had to educate application owners across their organization, and rely on them to always comply with IP allocation best practices. IPAM policies improve your operational model multi-fold. Now, you can add IP based filters in your networking and security constructs like access control lists, route tables, security groups, and firewalls, with confidence that public IPv4 addresses assignments to AWS resources always come from specific IPAM pools. The feature is available in all AWS commercial regions and the AWS GovCloud (US) Regions, in both Free Tier and Advanced Tier of VPC IPAM. When used with the Advanced Tier of VPC IPAM, customers can set policies across AWS accounts and AWS regions. To get started please see the https://docs.aws.amazon.com/vpc/latest/ipam/define-public-ipv4-allocation-strategy-with-ipam-policies.html. To learn more about IPAM, view the https://docs.aws.amazon.com/vpc/latest/ipam/what-it-is-ipam.html. For details on pricing, refer to the IPAM tab on the https://www.amazonaws.cn/en/vpc/pricing/.
aws.amazon.com
November 19, 2025 at 10:05 PM
Amazon VPC IPAM automates IP assignments from Infoblox IPAM

Today, AWS launched the ability for Amazon VPC IP Address Manager (IPAM) to automatically acquire non-overlapping IP address allocations from Infoblox Universal IPAM. This feature minimizes manual processes between cl...

#AWS #AmazonVpc
Amazon VPC IPAM automates IP assignments from Infoblox IPAM
Today, AWS launched the ability for Amazon VPC IP Address Manager (IPAM) to automatically acquire non-overlapping IP address allocations from Infoblox Universal IPAM. This feature minimizes manual processes between cloud and on-premises administrators, reducing the turnaround time. With this launch, you can automatically acquire non-overlapping IP addresses from your on-premises Infoblox Universal IPAM into your top-level AWS IPAM pool and organize them into regional pools based on your business requirements. When you acquire non-overlapping IPs, you reduce the risk of service disruptions because your IPs don’t conflict with on-premise IP addresses. Previously, in hybrid cloud environments, administrators had to use offline means such as tickets or emails to request and allocate IP addresses, which was often error-prone and time-consuming. This integration automates the manual process, improving operational efficiency. This feature is available in all https://aws.amazon.com/about-aws/global-infrastructure/regional-product-services/ where Amazon VPC IPAM is supported, excluding AWS China Regions and AWS GovCloud (US) Regions. To learn more about IPAM, view the https://docs.aws.amazon.com/vpc/latest/ipam/integrate-infoblox-ipam.html. For details on pricing, refer to the IPAM tab on the https://aws.amazon.com/vpc/pricing/.
aws.amazon.com
November 17, 2025 at 8:05 PM
AWS extends Traffic Mirroring support on new instance types

Amazon Virtual Private Cloud (Amazon VPC) Traffic Mirroring is now supported on additional instance types. Amazon VPC Traffic Mirroring allows you to replicate the network tra...

#AWS #AmazonVirtualPrivateCloud #AmazonVpc #AwsGovcloudUs
AWS extends Traffic Mirroring support on new instance types
Amazon Virtual Private Cloud (Amazon VPC) Traffic Mirroring is now supported on additional instance types. Amazon VPC Traffic Mirroring allows you to replicate the network traffic from EC2 instances within your VPC to security and monitoring appliances for use cases such as content inspection, threat monitoring, and troubleshooting. With this release, VPC Traffic Mirroring can be enabled on all Nitro v4 instances. You can see the complete list of instances that support VPC Traffic Mirroring in our https://docs.aws.amazon.com/vpc/latest/mirroring/what-is-traffic-mirroring.html#supported-instance-types. You can see the complete list of instances built on different Nitro system versions in our https://docs.aws.amazon.com/ec2/latest/instancetypes/ec2-nitro-instances.html. VPC Traffic Mirroring is supported on these additional instance types in all regions. To learn more about VPC Traffic Mirroring, please visit the VPC Traffic Mirroring https://docs.aws.amazon.com/vpc/latest/mirroring/what-is-traffic-mirroring.html. 
aws.amazon.com
August 28, 2025 at 8:05 PM
🆕 AWS GovCloud (US) now offers VPC Reachability and Network Access Analyzers to diagnose network issues and secure VPCs. Available in US-West and US-East regions. For details, see VPC documentation and pricing.

#AWS #AmazonVpc
Amazon VPC Reachability Analyzer and Amazon VPC Network Access Analyzer are now available in AWS GovCloud (US) Regions
With this launch, Amazon VPC Reachability Analyzer and Amazon VPC Network Access Analyzer are now available in both AWS GovCloud (US-West) and AWS GovCloud (US-East) Regions. VPC Reachability Analyzer allows you to diagnose network reachability between a source resource and a destination resource in your virtual private clouds (VPCs) by analyzing your network configurations. For example, Reachability Analyzer can help you identify a missing route table entry in your VPC route table that could be blocking network reachability between an EC2 instance in Account A that is not able to connect to another EC2 instance in Account B in your AWS Organization. VPC Network Access Analyzer allows you to identify unintended network access to your AWS resources, helping you meet your security and compliance guidelines. For example, you can create a scope to verify that all paths from your web-applications to the internet, traverse the firewall, and detect any paths that bypass the firewall. For more information, visit documentation for VPC Reachability Analyzer and VPC Network Access Analyzer. For pricing, refer to the Network Analysis tab on the Amazon VPC Pricing Page.
aws.amazon.comabout-aws
October 24, 2025 at 9:40 PM