By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: AWS Launches Network Firewall Proxy in Preview to Simplify Managed Egress Security
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > AWS Launches Network Firewall Proxy in Preview to Simplify Managed Egress Security
News

AWS Launches Network Firewall Proxy in Preview to Simplify Managed Egress Security

News Room
Last updated: 2025/12/27 at 5:22 AM
News Room Published 27 December 2025
Share
AWS Launches Network Firewall Proxy in Preview to Simplify Managed Egress Security
SHARE

AWS recently launched a preview of the AWS Network Firewall proxy, a managed service for proxy management and deployment. According to the company, this service allows customers to focus more on the security policies governing outbound access from their VPCs.

The Network Firewall proxy is integrated with the NAT Gateway service, which operates within the VPC and handles IP address translation for outgoing traffic. Users’ applications can connect to the proxy from both local and remote VPCs via a proxy-specific VPC interface endpoint powered by AWS PrivateLink.

(Source: AWS Network & Connectivity Blog)

Unlike traditional transparent firewalls, the proxy inspects network traffic by handling HTTP CONNECT requests and establishing connections on behalf of applications. It evaluates traffic in a sequential three-phase model:

  1. PreDNS: Evaluated before the proxy resolves the destination domain.
  2. PreRequest: Evaluated before the proxy sends the request to the destination.
  3. PostResponse: Evaluated after the proxy receives the response from the server.

 

Access rules are applied at each stage; if traffic is blocked in an earlier phase, subsequent phases do not trigger, optimizing processing efficiency.

 

Users can configure the Network Firewall’s proxy to either intercept TLS or allow TLS to pass through untouched. In case TLS interception is enabled, the proxy generates a certificate for the real destination, allowing it to inspect HTTP-layer content and apply policies. However, the workload must trust the proxy’s certificate authority. In contrast, when interception is disabled, an end-to-end encrypted tunnel is established directly between the workload and the destination, preventing the proxy from decrypting the payload and limiting policy enforcement to unencrypted metadata such as DNS, IP addresses, or SNI.

Architecturally, the service supports both distributed (per-VPC) and centralized models. In centralized setups, engineers can leverage Transit Gateway or Cloud WAN to route egress traffic from multiple VPCs to a single proxy endpoint, significantly reducing the administrative “tax” of patching and scaling traditional self-hosted Squid fleets. However, a key limitation remains, as Ivo Pinto points out in a LinkedIn post: the proxy is strictly for HTTP/HTTPS traffic, making it a specialized tool rather than a general-purpose network firewall.

The authors of the blog post on Network Firewall Proxy write:

Network Firewall proxy can be used to protect traffic from the local VPC, remote VPC, or even on-premises sources. As long as your workload has connectivity to the proxy endpoint, it can use the proxy service. Note that traffic can only reach the proxy through an endpoint. If you simply route traffic to the NAT Gateway, it will not apply proxy policies on it.

Currently, the service is available in the East Ohio AWS region and in preview. Kayesee commented in a Reddit thread:

Best to try it out. It is free in the Public Preview phase. It’s essentially a managed explicit forward proxy. You can configure rules for traffic from specific locations (e.g., VPC, account, or CIDR) to be whitelisted/blacklisted for specific websites. The workloads have to be proxy-aware (explicit).

Lastly, more details are available on the documentation pages.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Apple seeks to appeal against £1.5bn ruling it overcharged UK customers Apple seeks to appeal against £1.5bn ruling it overcharged UK customers
Next Article I forced Gemini and ChatGPT to fight over Android vs iOS, and we finally have a winner I forced Gemini and ChatGPT to fight over Android vs iOS, and we finally have a winner
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Ring Cancels Deal With Flock Safety Amid Surveillance Concerns
Ring Cancels Deal With Flock Safety Amid Surveillance Concerns
News
Helion reaches record 150 million degrees Celsius as it strives for ambitious commercial fusion launch
Helion reaches record 150 million degrees Celsius as it strives for ambitious commercial fusion launch
Computing
Anthropic raises bn in latest round, valuing Claude bot maker at 0bn
Anthropic raises $30bn in latest round, valuing Claude bot maker at $380bn
News
Win a Ninja Luxe Cafe Pro Coffee Machine!
Win a Ninja Luxe Cafe Pro Coffee Machine!
Gadget

You Might also Like

Ring Cancels Deal With Flock Safety Amid Surveillance Concerns
News

Ring Cancels Deal With Flock Safety Amid Surveillance Concerns

5 Min Read
Anthropic raises bn in latest round, valuing Claude bot maker at 0bn
News

Anthropic raises $30bn in latest round, valuing Claude bot maker at $380bn

5 Min Read
Best DJI deal: Save 9 on DJI Mini 5 Pro Fly More Combo
News

Best DJI deal: Save $509 on DJI Mini 5 Pro Fly More Combo

3 Min Read
Apple’s iOS 26.3 Security Update Addresses A Huge iPhone Exploit – BGR
News

Apple’s iOS 26.3 Security Update Addresses A Huge iPhone Exploit – BGR

4 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?