Home icon

Securing Egress Architectures with Network Firewall Proxy

Networking & Content Delivery Blog



This article introduces AWS Network Firewall proxy (preview), a managed proxy service that simplifies egress traffic security by eliminating self-managed proxy deployment and scaling challenges.

  • Integrated with NAT Gateway; filters traffic before reaching Internet, AWS, or on-premises destinations
  • Inspects traffic at three phases: PreDNS, PreRequest, and PostResponse for granular policy control
  • Supports optional TLS interception for HTTP-layer inspection or pass-through for end-to-end encryption
  • Setup requires: create rule groups, configure proxy with NAT Gateway, explicitly configure client applications
  • Supports distributed or centralized deployment models across multiple VPCs using endpoints or Transit Gateway
  • Can combine with traditional firewalling for mixed HTTP and non-HTTP traffic handling
  • Currently supports HTTP/HTTPS traffic only; IPv4 only in preview

Network Firewall proxy provides managed egress security with flexible deployment patterns, reducing operational overhead for organizations controlling outbound access.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Nov 25
2025
Introducing AWS Network Firewall Proxy in preview
Apr 1
2024
TLS inspection configuration for encrypted egress traffic and AWS Network Firewall
Oct 25
2024
Simplify firewall deployments using centralized inspection architecture with Gateway Load Balancer
Jun 23
2025
Securing Service Communications: Combining VPC Lattice with Network Firewall

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.