Existing VPC Network Guide
This guide helps you to prepare your VPC and debug networking issues using the fulfillment option Existing VPC.
You can stop reading if you use the fulfillment option Dedicated public VPC or Dedicated private VPC.
Required outbound communication
To reach AWS APIs, allow outbound TCP/443. If you use bucketAV in a VPC with enableDnsSupport set to false, you also have to allow outbound TCP/53 and UDP/53 to reach DNS.
The following outbound requests are made (replace REGION with AWS Region, e.g., us-east-1; get the value from the top right in the AWS UI).
| Endpoint | VPC Interface/Gateway service name | Description |
|---|---|---|
https://sns.REGION.amazonaws.com | com.amazonaws.REGION.sns | SNS API to publish scan results to the Findings Topic. |
https://events.REGION.amazonaws.com | com.amazonaws.REGION.events | EventBridge API to publish scan results (if ReportEventBridge configuration parameter is set to true). |
https://sqs.REGION.amazonaws.com | com.amazonaws.REGION.sqs | SQS API to read from the Scan Queue. |
https://s3.REGION.amazonaws.com | com.amazonaws.REGION.s3 | S3 API to interact with files; also required for cfn-init and cfn-signal tools and Amazon Linux 2023 repository. |
https://s3.amazonaws.com | com.amazonaws.REGION.s3 | S3 API to interact with files; also required for cfn-init and cfn-signal tools and Amazon Linux 2023 repository. |
https://autoscaling.REGION.amazonaws.com | com.amazonaws.REGION.autoscaling | EC2 Auto Scaling API to use ASG lifecycle hooks. |
https://monitoring.REGION.amazonaws.com | com.amazonaws.REGION.monitoring | CloudWatch API to publish memory, disk, and swap metrics. |
https://logs.REGION.amazonaws.com | com.amazonaws.REGION.logs | CloudWatch Logs API to publish logs. |
https://cloudformation.REGION.amazonaws.com | com.amazonaws.REGION.cloudformation | CloudFormation API required for cfn-init and cfn-signal tools. |
https://ssm.REGION.amazonaws.com | com.amazonaws.REGION.ssm | SSM API for Session Manager (if SystemsManagerAccess configuration parameter is set to true) |
https://ssmmessages.REGION.amazonaws.com | com.amazonaws.REGION.ssmmessages | SSM API for Session Manager (if SystemsManagerAccess configuration parameter is set to true) |
https://ec2messages.REGION.amazonaws.com | com.amazonaws.REGION.ec2messages | SSM API for Session Manager (if SystemsManagerAccess configuration parameter is set to true) |
https://dynamodb.REGION.amazonaws.com | com.amazonaws.REGION.dynamodb | DynamoDB API to fetch account information (if AWSAccountRestriction or AWSOrganizationRestriction configuration parameter is configured). |
https://sts.REGION.amazonaws.com | com.amazonaws.REGION.sts | STS API to assume IAM roles in other accounts (if AWSAccountRestriction or AWSOrganizationRestriction configuration parameter is configured). |
https://secretsmanager.REGION.amazonaws.com | com.amazonaws.REGION.secretsmanager | SecretsManager API to access private key, Cloudflare API token and secret key (for platform Amazon S3 only if SignCallbackInvocations configuration parameter is set to true). |
https://metering.marketplace.REGION.amazonaws.com | not available, use HttpsProxy configuration parameter or NAT Gateway | AWS Marketplace Metering API to to report usage. |
https://REGION.savmirror.bucketav.com | not available, use HttpsProxy configuration parameter or NAT Gateway | bucketAV API to fetch Sophos manifest for signatures and engine update. |
| Endpoint | VPC Interface/Gateway service name | Description |
|---|---|---|
https://sns.REGION.amazonaws.com | com.amazonaws.REGION.sns | SNS API to publish scan results to the Findings Topic. |
https://events.REGION.amazonaws.com | com.amazonaws.REGION.events | EventBridge API to publish scan results (if ReportEventBridge configuration parameter is set to true). |
https://sqs.REGION.amazonaws.com | com.amazonaws.REGION.sqs | SQS API to read from the Scan Queue. |
https://s3.REGION.amazonaws.com | com.amazonaws.REGION.s3 | S3 API to interact with files; also required for cfn-init and cfn-signal tools and Amazon Linux 2023 repository. |
https://s3.amazonaws.com | com.amazonaws.REGION.s3 | S3 API to interact with files; also required for cfn-init and cfn-signal tools and Amazon Linux 2023 repository. |
https://autoscaling.REGION.amazonaws.com | com.amazonaws.REGION.autoscaling | EC2 Auto Scaling API to use ASG lifecycle hooks. |
https://monitoring.REGION.amazonaws.com | com.amazonaws.REGION.monitoring | CloudWatch API to publish memory, disk, and swap metrics. |
https://logs.REGION.amazonaws.com | com.amazonaws.REGION.logs | CloudWatch Logs API to publish logs. |
https://cloudformation.REGION.amazonaws.com | com.amazonaws.REGION.cloudformation | CloudFormation API required for cfn-init and cfn-signal tools. |
https://ssm.REGION.amazonaws.com | com.amazonaws.REGION.ssm | SSM API for Session Manager (if SystemsManagerAccess configuration parameter is set to true) |
https://ssmmessages.REGION.amazonaws.com | com.amazonaws.REGION.ssmmessages | SSM API for Session Manager (if SystemsManagerAccess configuration parameter is set to true) |
https://ec2messages.REGION.amazonaws.com | com.amazonaws.REGION.ec2messages | SSM API for Session Manager (if SystemsManagerAccess configuration parameter is set to true) |
https://dynamodb.REGION.amazonaws.com | com.amazonaws.REGION.dynamodb | DynamoDB API to fetch account information (if AWSAccountRestriction or AWSOrganizationRestriction configuration parameter is configured). |
https://sts.REGION.amazonaws.com | com.amazonaws.REGION.sts | STS API to assume IAM roles in other accounts (if AWSAccountRestriction or AWSOrganizationRestriction configuration parameter is configured). |
https://secretsmanager.REGION.amazonaws.com | com.amazonaws.REGION.secretsmanager | SecretsManager API to access private key, Cloudflare API token and secret key (for platform Amazon S3 only if SignCallbackInvocations configuration parameter is set to true). |
| Endpoint | VPC Interface/Gateway service name | Description |
|---|---|---|
https://sns.REGION.amazonaws.com | com.amazonaws.REGION.sns | SNS API to publish scan results to the Findings Topic. |
https://events.REGION.amazonaws.com | com.amazonaws.REGION.events | EventBridge API to publish scan results (if ReportEventBridge configuration parameter is set to true). |
https://sqs.REGION.amazonaws.com | com.amazonaws.REGION.sqs | SQS API to read from the Scan Queue. |
https://s3.REGION.amazonaws.com | com.amazonaws.REGION.s3 | S3 API to interact with files; also required for cfn-init and cfn-signal tools and Amazon Linux 2023 repository. |
https://s3.amazonaws.com | com.amazonaws.REGION.s3 | S3 API to interact with files; also required for cfn-init and cfn-signal tools and Amazon Linux 2023 repository. |
https://autoscaling.REGION.amazonaws.com | com.amazonaws.REGION.autoscaling | EC2 Auto Scaling API to use ASG lifecycle hooks. |
https://monitoring.REGION.amazonaws.com | com.amazonaws.REGION.monitoring | CloudWatch API to publish memory, disk, and swap metrics. |
https://logs.REGION.amazonaws.com | com.amazonaws.REGION.logs | CloudWatch Logs API to publish logs. |
https://cloudformation.REGION.amazonaws.com | com.amazonaws.REGION.cloudformation | CloudFormation API required for cfn-init and cfn-signal tools. |
https://ssm.REGION.amazonaws.com | com.amazonaws.REGION.ssm | SSM API for Session Manager (if SystemsManagerAccess configuration parameter is set to true) |
https://ssmmessages.REGION.amazonaws.com | com.amazonaws.REGION.ssmmessages | SSM API for Session Manager (if SystemsManagerAccess configuration parameter is set to true) |
https://ec2messages.REGION.amazonaws.com | com.amazonaws.REGION.ec2messages | SSM API for Session Manager (if SystemsManagerAccess configuration parameter is set to true) |
https://dynamodb.REGION.amazonaws.com | com.amazonaws.REGION.dynamodb | DynamoDB API to fetch account information (if AWSAccountRestriction or AWSOrganizationRestriction configuration parameter is configured). |
https://sts.REGION.amazonaws.com | com.amazonaws.REGION.sts | STS API to assume IAM roles in other accounts (if AWSAccountRestriction or AWSOrganizationRestriction configuration parameter is configured). |
https://secretsmanager.REGION.amazonaws.com | com.amazonaws.REGION.secretsmanager | SecretsManager API to access private key, Cloudflare API token and secret key (for platform Amazon S3 only if SignCallbackInvocations configuration parameter is set to true). |
https://metering.marketplace.REGION.amazonaws.com | not available, use HttpsProxy configuration parameter or NAT Gateway | AWS Marketplace Metering API to to report usage. |
https://REGION.savmirror.bucketav.com | not available, use HttpsProxy configuration parameter or NAT Gateway | bucketAV API to fetch Sophos manifest for signatures and engine update. |
https://CLOUDFLARE_ACCOUNT_ID.r2.cloudflarestorage.com | not available, use HttpsProxy configuration parameter or NAT Gateway | Cloudflare API to access R2 buckets. |
| Endpoint | VPC Interface/Gateway service name | Description |
|---|---|---|
https://sns.REGION.amazonaws.com | com.amazonaws.REGION.sns | SNS API to publish scan results to the Findings Topic. |
https://events.REGION.amazonaws.com | com.amazonaws.REGION.events | EventBridge API to publish scan results (if ReportEventBridge configuration parameter is set to true). |
https://sqs.REGION.amazonaws.com | com.amazonaws.REGION.sqs | SQS API to read from the Scan Queue. |
https://s3.REGION.amazonaws.com | com.amazonaws.REGION.s3 | S3 API to interact with files; also required for cfn-init and cfn-signal tools and Amazon Linux 2023 repository. |
https://s3.amazonaws.com | com.amazonaws.REGION.s3 | S3 API to interact with files; also required for cfn-init and cfn-signal tools and Amazon Linux 2023 repository. |
https://autoscaling.REGION.amazonaws.com | com.amazonaws.REGION.autoscaling | EC2 Auto Scaling API to use ASG lifecycle hooks. |
https://monitoring.REGION.amazonaws.com | com.amazonaws.REGION.monitoring | CloudWatch API to publish memory, disk, and swap metrics. |
https://logs.REGION.amazonaws.com | com.amazonaws.REGION.logs | CloudWatch Logs API to publish logs. |
https://cloudformation.REGION.amazonaws.com | com.amazonaws.REGION.cloudformation | CloudFormation API required for cfn-init and cfn-signal tools. |
https://ssm.REGION.amazonaws.com | com.amazonaws.REGION.ssm | SSM API for Session Manager (if SystemsManagerAccess configuration parameter is set to true) |
https://ssmmessages.REGION.amazonaws.com | com.amazonaws.REGION.ssmmessages | SSM API for Session Manager (if SystemsManagerAccess configuration parameter is set to true) |
https://ec2messages.REGION.amazonaws.com | com.amazonaws.REGION.ec2messages | SSM API for Session Manager (if SystemsManagerAccess configuration parameter is set to true) |
https://dynamodb.REGION.amazonaws.com | com.amazonaws.REGION.dynamodb | DynamoDB API to fetch account information (if AWSAccountRestriction or AWSOrganizationRestriction configuration parameter is configured). |
https://sts.REGION.amazonaws.com | com.amazonaws.REGION.sts | STS API to assume IAM roles in other accounts (if AWSAccountRestriction or AWSOrganizationRestriction configuration parameter is configured). |
https://secretsmanager.REGION.amazonaws.com | com.amazonaws.REGION.secretsmanager | SecretsManager API to access private key, Cloudflare API token and secret key (for platform Amazon S3 only if SignCallbackInvocations configuration parameter is set to true). |
https://CLOUDFLARE_ACCOUNT_ID.r2.cloudflarestorage.com | not available, use HttpsProxy configuration parameter or NAT Gateway | Cloudflare API to access R2 buckets. |
You can’t restrict the IP address range. The resolved IP addresses change frequently.
If you are using an endpoint policy to protect your S3 VPC gateway interface, you must allowlist the S3 buckets you want bucketAV to access and the bucketAV S3 bucket to download signature updates from (replace REGION with AWS Region, e.g., us-east-1; get the value from the top right in the AWS UI).
{
"Version": "2012-10-17",
"Statement": [{
"Effect": "Allow",
"Principal": "*",
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::bucketav-clamav-mirror-REGION/*"
}, {
"Effect": "Allow",
"Principal": "*",
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::bucketav-release-data/*"
}]
}
{
"Version": "2012-10-17",
"Statement": [{
"Effect": "Allow",
"Principal": "*",
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::bucketav-sophos-mirror-REGION/*"
}, {
"Effect": "Allow",
"Principal": "*",
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::bucketav-release-data/*"
}]
}
If you set the SophosLiveProtectionCloudLookups configuration parameter to true, DNS queries for *.sophosxl.net must be resolvable.
Required outbound communication of Lambda functions
Requires bucketAV for Amazon S3 powered by ClamAV® version >= 2.27.0, bucketAV for Amazon S3 powered by Sophos® version >= 2.19.0, bucketAV for Cloudflare R2 powered by ClamAV® version >= 2.6.0, or bucketAV for Cloudflare R2 powered by Sophos® version >= 2.6.0.
To update to the latest version, follow the Update Guide.
By default, bucketAV runs its Lambda functions outside your VPC with direct access to AWS APIs and the Internet. No additional network configuration is required in this case.
Optionally, use the LambdaSubnets configuration parameter to run the Lambda functions in your VPC. When doing so, you must ensure that the configured subnets provide outbound TCP/443 (HTTPS) connectivity to the endpoints listed below via a NAT Gateway or VPC Endpoints. bucketAV attaches a security group to the Lambda functions that allows outbound HTTPS traffic; you do not need to provide a security group.
For example, the dashboard is powered by a Lambda function (DashboardLambda). If the Lambda functions cannot reach the required endpoints, the dashboard widgets fail with timeouts.
The following outbound requests are made (replace REGION with AWS Region, e.g., us-east-1; get the value from the top right in the AWS UI).
| Endpoint | VPC Interface/Gateway service name | Description |
|---|---|---|
https://cloudformation.REGION.amazonaws.com | com.amazonaws.REGION.cloudformation | CloudFormation API to read the deployed bucketAV and add-on versions and configuration. |
https://dynamodb.REGION.amazonaws.com | com.amazonaws.REGION.dynamodb | DynamoDB API to access the bucket cache and account connection tables (multi-account setup only). |
https://events.REGION.amazonaws.com | com.amazonaws.REGION.events | EventBridge API to check the real-time file scan configuration. |
https://logs.REGION.amazonaws.com | com.amazonaws.REGION.logs | CloudWatch Logs API to query the scan results shown on the dashboard. |
https://monitoring.REGION.amazonaws.com | com.amazonaws.REGION.monitoring | CloudWatch API used by the governance feature. |
https://organizations.us-east-1.amazonaws.com | not available, use NAT Gateway (see note below) | Organizations API for service discovery (multi-account setup only). |
https://s3.REGION.amazonaws.com | com.amazonaws.REGION.s3 | S3 API to check the bucket configuration, fetch reports, and respond to CloudFormation custom resources. |
https://secretsmanager.REGION.amazonaws.com | com.amazonaws.REGION.secretsmanager | Secrets Manager API to read and write secrets (e.g., the private key used to sign callback invocations). |
https://securityhub.REGION.amazonaws.com | com.amazonaws.REGION.securityhub | Security Hub API (if the deprecated SecurityHubIntegration configuration parameter is set to true; only available < v3, use the Security Hub integration Add-On instead). |
https://sns.REGION.amazonaws.com | com.amazonaws.REGION.sns | SNS API to check the subscriptions of the Findings Topic. |
https://ssm.REGION.amazonaws.com | com.amazonaws.REGION.ssm | SSM API to read add-on versions from the Parameter Store. |
https://states.REGION.amazonaws.com | com.amazonaws.REGION.states | Step Functions API to refresh the bucket cache (multi-account setup only). |
https://sts.REGION.amazonaws.com | com.amazonaws.REGION.sts | STS API to assume roles in connected accounts (multi-account setup only). |
https://bucketav-release-data.s3.eu-west-1.amazonaws.com | not available, use NAT Gateway (see note below) | Fetches information about the latest bucketAV releases to power the dashboard and the update check. |
| Endpoint | VPC Interface/Gateway service name | Description |
|---|---|---|
https://cloudformation.REGION.amazonaws.com | com.amazonaws.REGION.cloudformation | CloudFormation API to read the deployed bucketAV and add-on versions and configuration. |
https://logs.REGION.amazonaws.com | com.amazonaws.REGION.logs | CloudWatch Logs API to query the scan results shown on the dashboard. |
https://s3.REGION.amazonaws.com | com.amazonaws.REGION.s3 | S3 API to fetch reports and respond to CloudFormation custom resources. |
https://secretsmanager.REGION.amazonaws.com | com.amazonaws.REGION.secretsmanager | Secrets Manager API to read the Cloudflare API token and write secrets (e.g., the private key used to sign callback invocations). |
https://ssm.REGION.amazonaws.com | com.amazonaws.REGION.ssm | SSM API to read add-on versions from the Parameter Store. |
https://api.cloudflare.com | not available, use NAT Gateway | Cloudflare API to check the bucket configuration and manage queue consumers. |
https://bucketav-release-data.s3.eu-west-1.amazonaws.com | not available, use NAT Gateway (see note below) | Fetches information about the latest bucketAV releases to power the dashboard and the update check. |
The bucketAV release data is stored in an S3 bucket in
eu-west-1. An S3 VPC gateway endpoint only routes traffic to S3 in the same region. Therefore, unless you deploy bucketAV ineu-west-1, the Lambda functions require a route to the Internet (NAT Gateway) to reachhttps://bucketav-release-data.s3.eu-west-1.amazonaws.com. If you deploy bucketAV ineu-west-1and use an endpoint policy, allowlistarn:aws:s3:::bucketav-release-data/*as described above.
The Organizations API is only available in
us-east-1. The VPC interface endpointcom.amazonaws.us-east-1.organizationsis only available when you deploy bucketAV inus-east-1. Therefore, unless you deploy bucketAV inus-east-1, the Lambda functions require a route to the Internet (NAT Gateway) to reachhttps://organizations.us-east-1.amazonaws.com.
Many add-ons deploy Lambda functions as well and provide the LambdaVpc and LambdaSubnets parameters. The required endpoints differ per add-on and are documented on each add-on’s page.
Debug network issues
If you follow the Setup Guide, we advise you to skip the CloudFormation Configure stack options step and tell you to “Scroll to the bottom of the page and click on Next”. To debug a networking issue, you must set the Stack failure options to Preserve successfully provisioned resources to avoid a stack rollback. After fixing the issues, please remove the CloudFormation stack and start from scratch.
Connect to one of the bucketAV EC2 instances (Session Manager is likely not working if the network configuration is not yet complete).
To avoid instance termination because of a scale-in, set the AutoScalingMinSize configuration parameter to 1.
Requires bucketAV for Amazon S3 powered by ClamAV® version >= 2.8.0, bucketAV for Amazon S3 powered by Sophos® version >= 2.0.0, bucketAV for Cloudflare R2 powered by ClamAV® version >= 2.0.0, or bucketAV for Cloudflare R2 powered by Sophos® version >= 2.0.0.
To update to the latest version, follow the Update Guide.
Run the test script:
sudo /home/ec2-user/networktest.sh
The script output should look like this.
[SUCCESS] Connected to SNS successfully.
[SUCCESS] Connected to SQS successfully.
[SUCCESS] Connected to S3 (Region) successfully.
[SUCCESS] Connected to S3 (HTTP) successfully.
[SUCCESS] Connected to S3 (Global) successfully.
[SUCCESS] Connected to EC2 Auto Scaling successfully.
[SUCCESS] Connected to CloudWatch Monitoring successfully.
[SUCCESS] Connected to CloudWatch Logs successfully.
[SUCCESS] Connected to CloudFormation successfully.
[SUCCESS] Connected to SSM successfully.
[SUCCESS] Connected to SSM Messages successfully.
[SUCCESS] Connected to EC2 Messages successfully.
[SUCCESS] Connected to DynamoDB successfully.
[SUCCESS] Connected to STS successfully.
[SUCCESS] Connected to SecretsManager successfully.
[SUCCESS] Connected to Marketplace Metering successfully.
[SUCCESS] Connected to ClamAV Mirror successfully.
[SUCCESS] Connected to Sophos mirror successfully.
[SUCCESS] Connected to Sophos mirror successfully.
[SUCCESS] Connected to Amazon Linux 2023 Repository successfully.
Watch out for [FAILURE] messages.
Fixing networking issues
As network configurations differ, we cannot provide a solution but we can give you some hints.
Internet Gateway
Check the routing table attached to the subnet of a bucketAV instance. In case the route table contains an entry for 0.0.0.0/0 pointing to an Internet Gateway (igw-) you are deploying bucketAV into a public subnet.
In this case, you must ensure that bucketAV attaches a public IP address when launching an EC2 instance. Set the AssociatePublicIpAddress configuration parameter to true.
Also, ensure that all subnets used by bucketAV (see the Subnets configuration parameter) use a routing table with an entry pointing to the Internet Gateway.
NAT Gateway
If you deployed bucketAV into a subnet without an Internet Gateway, you might use a typical VPC configuration with private and public subnets. Again, check the routing table attached to the subnet of a bucketAV instance. In case the route table contains an entry for 0.0.0.0/0 pointing to a NAT Gateway (ngw-) you are deploying bucketAV into a private subnet with access to a NAT Gateway.
- Verify that the Network Access Control List attached to the subnet used by bucketAV and the NAT Gateway allow outbound traffic on port
443(HTTPS) as well as inbound traffic on high ports. - Verify that all subnets used by bucketAV (see the Subnets configuration parameter) use a routing table with an entry pointing to the NAT Gateway.
VPC Endpoint
If the subnets are neither connected with an Internet Gateway nor a NAT Gateway, we recommend configuring VPC Endpoints for the AWS services required by bucketAV as described above.