Harden Multicloud AWS Network
Budget: $25 – $50 USD
I’m rolling out a highly available, multi-Availability-Zone network on AWS and need a seasoned cloud network engineer to turn my draft architecture into a production-ready environment.
What I already have
• A baseline design that routes all traffic through AWS Transit Gateway, links multiple VPCs and external clouds over Direct Connect, and relies on third-party firewalls running on EC2.
• Clear goals: comprehensive security inspection and governance for both inbound and outbound traffic, plus seamless multicloud integration.
What I want from you
• Validate and refine the architecture against AWS best practices for large-scale security and availability.
• Deploy the solution—Terraform or CloudFormation preferred—across at least two AZs, wiring up Transit Gateway attachments, route tables, and Direct Connect Gateway.
• Implement the firewall clusters (active-passive or autoscaling pair) on EC2, handle bootstrap licensing, and confirm all flows are inspected.
• Set up health checks, fail-over logic, and logging to CloudWatch and S3.
• Produce concise documentation: diagrams, build scripts, and an operations runbook.
Nice-to-haves
• Experience with Palo Alto, Fortinet, or Check Point firewall AMIs.
• Familiarity with AWS Gateway Load Balancer for potential future shift.
• Ability to run quick security posture reviews once traffic is live.
Deliverables
1. IaC templates ready for reuse
2. Deployed, tested environment in my AWS account
3. Network/security diagrams and runbook
If you’ve proven expertise in Transit Gateway-centric designs and deep hands-on work with third-party firewalls, let’s talk.
What I already have
• A baseline design that routes all traffic through AWS Transit Gateway, links multiple VPCs and external clouds over Direct Connect, and relies on third-party firewalls running on EC2.
• Clear goals: comprehensive security inspection and governance for both inbound and outbound traffic, plus seamless multicloud integration.
What I want from you
• Validate and refine the architecture against AWS best practices for large-scale security and availability.
• Deploy the solution—Terraform or CloudFormation preferred—across at least two AZs, wiring up Transit Gateway attachments, route tables, and Direct Connect Gateway.
• Implement the firewall clusters (active-passive or autoscaling pair) on EC2, handle bootstrap licensing, and confirm all flows are inspected.
• Set up health checks, fail-over logic, and logging to CloudWatch and S3.
• Produce concise documentation: diagrams, build scripts, and an operations runbook.
Nice-to-haves
• Experience with Palo Alto, Fortinet, or Check Point firewall AMIs.
• Familiarity with AWS Gateway Load Balancer for potential future shift.
• Ability to run quick security posture reviews once traffic is live.
Deliverables
1. IaC templates ready for reuse
2. Deployed, tested environment in my AWS account
3. Network/security diagrams and runbook
If you’ve proven expertise in Transit Gateway-centric designs and deep hands-on work with third-party firewalls, let’s talk.