Maintained with ☕️ by
IcePanel logo

[Preview Announcement] Re-introducing Forward Proxy as AWS Network Firewall Functionality

Share

Services

You can now use your Network Firewall with all its existing filtering capabilities and features as an explicit forward proxy. On Nov 25, 2025, AWS introduced Network Firewall _proxy_ in public preview to help customers exert centralized security controls against data exfiltration and malware injection. At the time, the Network Firewall _proxy_ was introduced as a standalone product, separate from Network Firewall _transparent firewall_ and used its own separate _proxy_ security policy. Customers who tested it in preview shared that they want the Network Firewall _proxy_ to maintain parity with Network Firewall’s existing set of capabilities and use the same security policy across the two functionalities_._ In keeping with customer feedback, we are reintroducing explicit _proxy_ as a functionality of Network Firewall. With this launch, you can configure Network Firewall with your existing Firewall policy in a new _no-source-preservation_ deployment where it can be used as an explicit _proxy_ with all its existing features including managed rule groups, active threat defense, Geo-IP filtering, URL and domain category filtering, container attribute-based rules for Amazon EKS and Amazon ECS, etc. You can create a single security policy and use it for both explicit _proxy_ and _transparent firewall_ functionalities. Try out AWS Network Firewall in _no-source-preservation_ deployment with _proxy_ functionality in your test environment today in US East (Ohio) region. _no-source-preservation_ Network Firewall is available for free during public preview. For more information, check [no-source-preservation Network Firewall documentation](https://docs.aws.amazon.com/network-firewall/latest/developerguide/nfw-no-source-preservation.html).