This topic explains how to configure clients to forward HTTP and HTTPS traffic through an explicit proxy firewall. It covers configurations for various environments, including Linux curl, Linux environment variables, the Windows system proxy, and agent-based tools like OpenCode.
The configurations described in this topic apply only to application-layer proxies. Only applications that recognize these settings will forward traffic through the explicit proxy firewall. To route all TCP/UDP traffic through a proxy, use the Internet Firewall solution instead.
Prerequisites
Configure an explicit proxy firewall in the Cloud Firewall console. For instructions, see explicit proxy firewall.
Obtain and record the required proxy information by clicking a proxy instance ID on the Explicit Proxy > Proxy Instance page.
Example proxy information
The examples in this topic use a sample explicit proxy address. Replace it with the address from your actual environment.
Parameter | Example value |
Proxy instance listening address |
|
Proxy instance listening port |
|
Proxy protocol | HTTP proxy |
Proxy URL |
|
General placeholders:
Placeholder | Description |
| The proxy address, for example, |
| The proxy port, for example, |
| The protocol prefix in the proxy address. This indicates the protocol used by the client to connect to the proxy. Currently, only |
Proxy environment variable fields:
HTTP_PROXY / http_proxy: The
http_proxyenvironment variable specifies the proxy for HTTP target requests. Thehttp://prefix in the proxy address indicates that the client connects to the proxy over the HTTP protocol.HTTPS_PROXY / https_proxy: The
https_proxyenvironment variable specifies a proxy for HTTPS target requests. However, the protocol for the proxy address itself currently supports onlyhttp://, which means the client connects to the proxy by using the HTTP protocol. Thehttps://protocol, which means the client connects to the proxy by using TLS, is not supported.NO_PROXY / no_proxy: A comma-separated list of hostnames or IP addresses to exclude from proxying. Common values include
localhost,127.0.0.1,::1.
Specify a proxy in Linux with curl
A client can connect to a proxy instance in the following ways, depending on its network location:
Same VPC: The client connects directly using the DNS domain name of the proxy instance as the proxy address.
Cross-VPC: The client can also use the DNS domain name of the proxy instance as its proxy address, provided that the proxy instance is routable from the client. The domain name resolves to the private IP address of the proxy instance.
Access an HTTP site
curl -sS -v -m 20 -x http://fw-****.proxy.cn-hangzhou.cfw.aliyuncs.com:10001 http://www.aliyun.comGeneric command:
curl -x http://<proxy_host>:<proxy_port> http://example.comAccess an HTTPS site
curl -sS -v -m 20 -x http://fw-****.proxy.cn-hangzhou.cfw.aliyuncs.com:10001 https://example.comGeneric command:
curl -x http://<proxy_host>:<proxy_port> https://example.comInspect the proxy connection process
curl -v -x http://<proxy_host>:<proxy_port> https://example.comIf HTTPS traffic is successfully routed through the proxy, the output typically includes the following lines:
CONNECT example.com:443 HTTP/1.1
HTTP/1.1 200 Connection establishedConfigure proxy with environment variables in Linux
Configure a temporary shell proxy
This configuration applies only to the current shell session and its child processes.
export http_proxy="http://<proxy_host>:<proxy_port>"
export https_proxy="http://<proxy_host>:<proxy_port>"
export HTTP_PROXY="http://<proxy_host>:<proxy_port>"
export HTTPS_PROXY="http://<proxy_host>:<proxy_port>"It is recommended to also configure addresses to bypass the proxy:
export no_proxy="localhost,127.0.0.1,::1"
export NO_PROXY="localhost,127.0.0.1,::1"Common bypass addresses:
Address | Description |
| Localhost access |
Verify the configuration:
curl -v https://example.comConfigure a permanent user proxy
Edit the shell configuration file:
vim ~/.bashrc # For Bash users vim ~/.zshrc # For Zsh usersAppend the following lines to the file:
export http_proxy="http://<proxy_host>:<proxy_port>" export https_proxy="http://<proxy_host>:<proxy_port>" export HTTP_PROXY="http://<proxy_host>:<proxy_port>" export HTTPS_PROXY="http://<proxy_host>:<proxy_port>" export no_proxy="localhost,127.0.0.1,::1" export NO_PROXY="localhost,127.0.0.1,::1"Apply the changes:
source ~/.bashrc # For Bash users source ~/.zshrc # For Zsh users
Configure a permanent, system-wide proxy
Create a system-wide proxy configuration file:
sudo vim /etc/profile.d/proxy.shAdd the following content:
export http_proxy="http://<proxy_host>:<proxy_port>" export https_proxy="http://<proxy_host>:<proxy_port>" export HTTP_PROXY="http://<proxy_host>:<proxy_port>" export HTTPS_PROXY="http://<proxy_host>:<proxy_port>" export no_proxy="localhost,127.0.0.1,::1" export NO_PROXY="localhost,127.0.0.1,::1"To apply the changes, log out and log back in, or run the following command for the current session:
source /etc/profile.d/proxy.sh
Configure proxy for agent or OpenCode
When using an agent, verify which proxy settings it reads, as this can vary.
Start an agent in an interactive CLI
The following example uses the OpenCode interactive CLI:
export HTTP_PROXY=http://fw-****.proxy.cn-hangzhou.cfw.aliyuncs.com:10001; export HTTPS_PROXY=http://fw-****.proxy.cn-hangzhou.cfw.aliyuncs.com:10001; timeout 300 opencode run --auto 'what is the weather in Hangzhou tomorrow'OpenCode reads system environment variables. If you have already configured the variables as described in the Linux environment variables section, you can start the interactive session directly. The agent traffic will automatically be routed through the explicit proxy:
timeout 300 opencode run --auto 'what is the weather in Hangzhou tomorrow'Configure the system proxy in Windows
Configure the proxy in Windows Settings
These steps are for Windows Server 2025. The procedure might differ on other Windows versions.
Open Settings.
Go to Network & Internet.
Go to Proxy.
Under Manual proxy setup, click Set up.
Enable Use a proxy server.
Set Address to
<proxy_host>.Set Port to
<proxy_port>.In the Use the proxy server except for addresses that start with the following entries box, enter exception addresses, such as
localhost;127.0.0.1;::1.Click Save.
This configuration applies to web browsers and other applications that respect the system proxy settings.