Cloud Network Defender final project · Bar-Ilan University · 2026
Four AWS accounts behind an on-premises Palo Alto firewall
A 97-step build on AWS, documented, then rebuilt in a second region and failed over in under two minutes.
Palo Alto Networks
Microsoft Entra ID
VMware Workstation Pro
Docker
PostgreSQL
Diagram 1 - network architecture
The build guide
Every step, written down
The whole build as it was done, one step at a time, readable here in full.
422pages
97steps
8parts
4appendices
1 / 422
Loading the reader
Reading the document index
Drawing the page
What it is
Four AWS accounts (management, R&D, IT, DevOps) under one organization, an on-premises Palo Alto firewall in front of all of them, and a real application running behind it. Built step by step on AWS, every step written down as it was done, then built a second time in a second region and failed over. Torn down at the end on purpose: the cost of the verified run was reconciled to the cent, and that only means something if nothing is left running.
Identity
Users come from Microsoft Entra ID into IAM Identity Center over SCIM, with MFA enforced; nobody signs in with an AWS password. Three permission sets, one per department, and what each one denies is the deliberate part; a fourth gives IT and DevOps network administration across all three accounts. The administrator role is break-glass only. The member accounts were created with no root password and none was ever set; centralized root access is what keeps it that way. A step exists purely to prove the groups are scoped the way the design says.
Guardrails
Service control policies limit which regions and which machine images any account can use. That is why a golden image pipeline had to exist at all: the guardrail makes the default images unusable, so the build has to produce its own. A different SSH key pair per department, EBS encryption by default, a five-dollar budget on every account, and a nightly Lambda that terminates untagged instances so nothing is left running by accident.
Network
Seven VPCs across Ireland and N. Virginia, private by default, twenty-eight security groups scoped tier by tier. Two transit gateways, one per region, shared across the accounts and deliberately not peered. Two site-to-site VPNs with two tunnels each to a PA-VM on VMware, configured on both sides. The transit gateway default routes point at the VPN, so everything hairpins through the Palo Alto, including traffic between the two AWS regions: Ireland to Virginia travels down to the firewall and back up, so one device inspects everything.
Diagram 2 - application layer
Firewall
App-ID policy, SSL decryption, inspection and logging on every route. Per-department address groups, so R&D in the US reaches R&D in Europe and nothing else. Zone protection profiles. QUIC blocked, so browsers cannot route around the decryption. 45 of the 97 steps are the firewall and the hybrid connectivity.
Application
ECS Fargate in private subnets with no public IPs and no NAT gateway in its path, reaching ECR, Secrets Manager and CloudWatch over interface endpoints and S3 over a gateway endpoint, so the containers have no internet path at all. PostgreSQL on RDS with credentials that rotate on their own, a shared EFS file system. An internet-facing load balancer that only CloudFront can reach, enforced two ways; the public name resolves to CloudFront, never to the load balancer. The app is the one this site serves today.
Storage and recovery
A shared bucket under customer-managed KMS keys, one per region, and a bucket policy that enforces access; each department reaches only its own folder, by Entra identity. Cross-region replication into a mirrored US bucket with a reverse rule back, a low-cost disaster recovery copy in Frankfurt, and ten days of safety on every deletion. The whole environment built again in N. Virginia; when the primary's load balancer was left with no healthy targets, a Route 53 health check moved the origin in 83 seconds and traffic followed with nobody touching anything. The honest limit, stated in the write-up: the database is the one component without automatic failover.
Diagram 3 - governance architecture
What broke
The interesting failures all lived in the seams between the layers, not in any one of them: a guardrail that quietly made the stock machine images unusable for the step after it; a firewall whose own update traffic broke under its own decryption in the course lab, a lesson the build carries as a standing exemption; a browser that would have walked straight past the decryption over QUIC if QUIC had not been blocked. The write-up, 97 steps, exists so the next person does not have to find them again.