Amazon Web Services Identity Router Deployment Models
To reduce the footprint of the identity router deployment in your on-premises network environment, you can deploy the identity router in the Amazon Web Services (AWS) cloud.
You can host all of your resources in the AWS Virtual Private Cloud (VPC), or connect your on-premises resources to one or more identity router instances hosted in the VPC. Each resource, including the identity router, can be part of a private or public subnet, or both, depending on connection requirements. If you deploy the identity router in a private subnet, you can deploy a NAT load balancer in the public subnet to direct traffic to and from the identity router.
If your deployment requires high availability, you can set up multiple identity routers in the VPC, and configure your Amazon environment so that each identity router is hosted in a different availability zone.
The following sections describe typical AWS deployments. Before setting up the identity router, refer to your AWS documentation and work with your network administrator to determine the appropriate deployment model to connect your organization's cloud-based and on-premises network resources.
Full Cloud Deployment
In a full cloud deployment, all of your network resources are deployed in the VPC. A router in the VPC manages traffic between public and private subnets containing the identity router, identity sources, and optional resources such as Authentication Manager. The resources within the VPC communicate with the Cloud Access Service (CAS)and protected web applications through an internet gateway.
Hybrid Cloud Deployment
In a hybrid cloud deployment, the identity router is deployed in the VPC either alone or in addition to other cloud-based instances, but resources such as identity sources and Authentication Manager are hosted on your on-premises network and connected to the VPC through a VPN gateway or AWS Direct Connect. As in the full cloud deployment, a router in the VPC manages traffic between subnets, and the identity router contacts CAS and web applications through an internet gateway.
Related Articles
Deploying an Identity Router (Video) 14Number of Views View Network Diagnostics on an Identity Router 35Number of Views Configure Network Settings Using the Identity Router Setup Console 92Number of Views DSA-2020-112: RSA Authentication Manager Security Update for Third Party Component Vulnerabilities 24Number of Views Configure Initial Network Settings Using the Identity Router VM Console 118Number of Views
Trending Articles
An example of SSO using SAML and ADFS with RSA Identity Management and Governance 6.9.x RSA Authentication Manager 8.9 Release Notes (January 2026) RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide Passwordless Authentication in Windows MFA Agent for Active Directory – Quick Setup Guide RSA Authentication Manager Upgrade Process