> For the complete documentation index, see [llms.txt](https://ghoulsec.gitbook.io/ghoulsec-vault/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ghoulsec.gitbook.io/ghoulsec-vault/cyber-security-base/cloud-security/amazon-web-services-aws/aws-bastion-host.md).

# AWS - Bastion Host

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2Fg65hdQMpiYaRgPh417Op%2Fimage.png?alt=media&amp;token=18c19391-d4da-456a-af08-89f620ee77b8" alt=""><figcaption><p>AWS Bastion Host Block Diagram</p></figcaption></figure>

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2FUXv7iMegRFjR4mr6BqFi%2Fimage.png?alt=media&amp;token=93b92686-4e8e-404c-92bc-e5a0b5ed9f30" alt=""><figcaption><p>Internet Gateway &#x26; Route Table setup</p></figcaption></figure>

Bastion host is basically a host available on internet (public) which works as the authentication mechanism which later allows the access to the machines & services running on the private subnet is what we called the bastion host.

To create the bastion host configuration we will have to follow the following steps :&#x20;

***

#### Steps to reproduce :&#x20;

1. Create a VPC named "your-vpc"
2. Create the Internet Gateway & attach it to the VPC Just created
3. Create two subnets (Public & Private)
4. Make the Routing table & attach only "PUBLIC" subnet as the subnet association and add the route to "Internal Gatway" to destination "0.0.0.0/0" to access internet on the public subnet
5. Now create the Public EC2 instance with associate VPC & enable the public IP to enable ssh access  to the instance
6. Now create the Private EC2 instance with associate VPC & disable the public IP to enable ssh only from the Public Instance just created.
7. Check the connectivity of the bastion host & check the subnets logs&#x20;

***

Now we have sucessfully configured the bastion host in the AWS - VPC
